Skip to content

Connect with a site API token

Connect Webflow with a site API token instead of signing in. The six permissions the token needs, why it reaches one site, and how to fix token errors.

Signing in to Webflow is the default way to connect it to Whalesync. A site API token is an alternative if you prefer not to sign in, or are setting up a sync through the API or MCP server and need a credential to hand over.

A token differs from signing in in three ways:

  • It does not expire.
  • It reaches only the site it was generated in.
  • It can be pasted into the API or given to an agent. A sign-in has to happen in a browser.
  1. In Webflow, open the site and go to Site settings > Apps & integrations.
  2. Under API access, click Generate API token.
  3. Name it Whalesync.
  4. Give it every permission listed below.
  5. Generate the token and copy it. Webflow shows it only once.

All six are required. Set each to read and write, except Authorized user, which is read-only.

Permission Why Whalesync needs it
CMS Read and write the items in your collections.
Sites Read your site, and publish it when a sync asks to.
Pages Read and update your site's pages.
Ecommerce Sync products and SKUs.
Users Whalesync's sign-in asks for it too. It was for syncing site users, which Webflow retired with Memberships.
Authorized user Read the account the token belongs to.

A token reaches only the site it was generated in, so a connection made with a token syncs that one site. To sync another site, create a connection with a token from that site.

Reauthorizing with a token from a different site is refused. Use a token generated in the site the connection syncs.

  1. In the connect step, choose Use a site API token instead.
  2. Paste the token and click Authorize.
  3. Pick the site.

A connection keeps its method. To switch between token and sign-in, create a new connection.

Message What to do
Webflow did not accept this site API token The token was copied wrong or deleted from the site settings. Copy it again, or generate a new one.
This site API token is missing a permission Whalesync needs Generate a new token with all six permissions above.
This site API token does not have access to a site this connection syncs The token is from another site. The message ends with the ID of the site the connection syncs, in parentheses; generate a token in that site.

Deleting the token in Webflow stops every sync using it until you reconnect with a new token.