Platforms

Permissions: manage_platforms

A platform is an integration identity: it lets an external system work with ioki Platform across one or more providers and products at once. Unlike an administrator, which is a person’s account, a platform is used by another backend to integrate with ioki Platform through the Platform API.

From this screen you can create platforms, control what each one can reach, assign its roles, and lock or archive it.

Create a platform

Create a new platform and enter:

  • Name. How the platform is identified in the list.
  • Description. An optional note about what the integration is for.
  • Locale. The default language for the platform.
  • Timezone identifier. The platform’s default time zone.

A platform starts with no access. You grant its access to providers, products, and operators separately.

Manage access

Selecting Manage Access controls which parts of the system a platform can reach:

  • Add the providers the platform is allowed to work with.
  • For each provider, choose the specific products and operators the platform can access.

Access is granted per provider and per product, so a single platform can be scoped tightly to exactly the services an integration needs.

Manage roles and permissions

Access on its own does not say what a platform may do—that comes from its roles. The roles and permissions overview shows the roles currently assigned to a platform and the permissions they grant, and lets you assign or withdraw roles.

Roles are assigned at more than one scope: global roles apply across everything the platform can reach, while Provider Roles and Product Roles are set for each provider the platform has access to. This lets a platform hold different permissions for different providers and products. Every Platform API request is then checked against the exact provider or product it targets: to create rides in a product, for example, the platform must hold a role granting that permission for that product. A platform can only act on the providers, products, and operators it has been given access to.

Lock or archive a platform

  • Lock temporarily disables a platform. A locked platform cannot authenticate to the Platform API until it is unlocked.
  • Archive retires a platform that is no longer needed.