Authentication Requirements
EAP integrations use OAuth 2.0.OAuth 2.0 (Required Default)
OAuth 2.0 is the recommended, required-by-default authentication model for partner integrations. It supports secure, scalable access across multiple customer accounts, lets customers authorise and revoke access independently, and gives your integration its own identity and audit trail.Integrated API Keys (Approved Exception Only)
Integrated API Keys remain restricted and are approved only as an exception, when your ERP or system can’t support OAuth 2.0. See the Integrated API Keys Overview.Standalone API Keys
You can use Standalone API Keys to explore Pleo’s APIs. We recommend you use OAuth 2.0 from the get-go, since it’s what your registered partner integration must authenticate with. EAP approval isn’t guaranteed. If you’re not approved as a Pleo Partner and you have a small number of small clients, you can use Standalone API Keys instead, which you’ll need to manage carefully. See Integration Design for Standalone API Keys. Once your clientele grows, you can register your intent again and Pleo will re-evaluate your interest.What Comes Next?
Go back to the Pleo Partners Quickstart and continue with the next step to register your integration intent.FAQs
Which authentication approach should an app serving multiple separate Pleo customers use instead of a single shared credential?
OAuth 2.0, required by default for all EAP-registered partner integrations. Integrated API Keys are allowed only as an approved exception when the partner’s ERP/system cannot support OAuth 2.0. See the Early Access Programme (EAP) for eligibility and registration details.
Can a multi-customer integration use Standalone API Keys instead of OAuth 2.0?
Only as a temporary fallback, not the required model. If an integration is not yet approved as a Pleo Partner through the EAP and has a small number of small clients, it can use Standalone API Keys in the meantime, managed carefully per customer. Once the partner’s clientele grows, they should re-register through the EAP and move to OAuth 2.0. See Integration Design for Standalone API Keys for how to manage this per-customer.