API Access Tokens
API Access Tokens authenticate external applications — such as WordPress, Zapier, or your own custom tools — to communicate with Kiflo. You can create multiple tokens and assign each one a descriptive name so you always know which application uses which token.Generate an API Access Token
1
Open Account Settings
Click your account menu in the top-right corner and select Account.
2
Go to Integration settings
In the left-hand menu, click Integration, then scroll down to the API Access Token section.
3
Add a new token
Click the Add button.
4
Name your token
Enter a descriptive name that identifies the application you are connecting (e.g.
WordPress, Zapier, or Custom CRM Integration).5
Confirm and copy
Click Add again to generate the token. Click the Paste button (copy to clipboard) to capture the token immediately.
Revoke an API Access Token
Revoke a token when you decommission an integration, suspect unauthorized access, or rotate credentials as part of your security policy. Revoking a token immediately prevents the associated application from connecting to your Kiflo account.1
Open Account Settings
Click your account menu in the top-right corner and select Account.
2
Go to Integration settings
In the left-hand menu, click Integration and scroll to the API Access Token section.
3
Select the token
Find the token you want to revoke in the list.
4
Revoke
Click Revoke, then click Yes, I’m sure in the confirmation dialog.
Single Sign-On (SSO)
SSO lets your team members sign in to Kiflo using your existing identity provider (IdP), such as Okta, Azure AD, or Google Workspace. This centralizes access management — when you offboard an employee in your IdP, their Kiflo access is revoked automatically.Set up SSO
1
Open Security settings
Go to Account Settings > Security.
2
Configure your identity provider
Follow the SSO setup guide for your IdP. You will need to provide Kiflo’s SSO metadata (available on the Security settings page) to your IdP, and provide your IdP’s metadata back to Kiflo.
3
Test the connection
Use the test flow in the Security settings to verify that authentication works correctly before enforcing SSO for all users.
4
Enforce SSO (optional)
Once verified, you can require all team members to sign in via SSO only.
Sign in with SSO
Once SSO is configured, team members can sign in to Kiflo using their company credentials:- Go to the Kiflo login page.
- Click Sign in with SSO.
- Enter your company email address.
- You will be redirected to your identity provider to authenticate.
- After successful authentication, you are returned to Kiflo and signed in.
If your administrator has enforced SSO, the standard email/password login option will not be available.
Multi-Factor Authentication (MFA)
MFA adds a second verification step to the Kiflo login process, significantly reducing the risk of unauthorized access even if a password is compromised.Enable MFA for your account
1
Open Security settings
Go to Account Settings > Security.
2
Enable MFA
Toggle on Multi-Factor Authentication.
3
Set up your authenticator app
Scan the QR code displayed in Kiflo with an authenticator app (such as Google Authenticator, Authy, or Microsoft Authenticator).
4
Verify
Enter the one-time code from your authenticator app to confirm setup. MFA is now active on your account.
