Central Command

An API-Key is a secret access credential that allows systems to access a programming interface programmatically. For Central Command, the most relevant keys are those for the Lexware Public API as well as keys or tokens for Clockify and Timebutler. Without valid authentication, vouchers, time entries, or absences cannot be synchronized reliably.

In practice, a dedicated key is stored per Lexware instance or connection. This enables multi-tenant operation with separate credentials and clear attribution. The public marketing website stores no keys; they belong exclusively in the protected app area. Good key management means rotation when staff changes, minimal permissions, and no sharing over insecure channels.

Central Command uses keys server-side and in combination with local caches as well as the rate limits of the respective APIs. This keeps the sync stable even when many instances are queried one after another. A compromised key should be revoked and replaced immediately. The API-Key is therefore less a feature of the user interface than the technical prerequisite for the entire command center operation.

This entry contains 170 words.

Björn Groenewold

Keep the conversation going?

Talk directly to Björn Groenewold about Central Command — free of charge and without obligation.

Dipl. Inf. Björn Groenewold · Managing Director