Connect with a site API token
Connect Webflow with a site API token instead of signing in. The six permissions the token needs, why it reaches one site, and how to fix token errors.
Signing in to Webflow is the default way to connect it to Whalesync. A site API token is an alternative if you prefer not to sign in, or are setting up a sync through the API or MCP server and need a credential to hand over.
A token differs from signing in in three ways:
- It does not expire.
- It reaches only the site it was generated in.
- It can be pasted into the API or given to an agent. A sign-in has to happen in a browser.
Generate the token
Section titled “Generate the token”- In Webflow, open the site and go to Site settings > Apps & integrations.
- Under API access, click Generate API token.
- Name it
Whalesync. - Give it every permission listed below.
- Generate the token and copy it. Webflow shows it only once.
Permissions
Section titled “Permissions”All six are required. Set each to read and write, except Authorized user, which is read-only.
| Permission | Why Whalesync needs it |
|---|---|
| CMS | Read and write the items in your collections. |
| Sites | Read your site, and publish it when a sync asks to. |
| Pages | Read and update your site's pages. |
| Ecommerce | Sync products and SKUs. |
| Users | Whalesync's sign-in asks for it too. It was for syncing site users, which Webflow retired with Memberships. |
| Authorized user | Read the account the token belongs to. |
One site per token
Section titled “One site per token”A token reaches only the site it was generated in, so a connection made with a token syncs that one site. To sync another site, create a connection with a token from that site.
Reauthorizing with a token from a different site is refused. Use a token generated in the site the connection syncs.
Paste the token into Whalesync
Section titled “Paste the token into Whalesync”- In the connect step, choose Use a site API token instead.
- Paste the token and click Authorize.
- Pick the site.
A connection keeps its method. To switch between token and sign-in, create a new connection.
Errors
Section titled “Errors”| Message | What to do |
|---|---|
| Webflow did not accept this site API token | The token was copied wrong or deleted from the site settings. Copy it again, or generate a new one. |
| This site API token is missing a permission Whalesync needs | Generate a new token with all six permissions above. |
| This site API token does not have access to a site this connection syncs | The token is from another site. The message ends with the ID of the site the connection syncs, in parentheses; generate a token in that site. |
Revoking the token
Section titled “Revoking the token”Deleting the token in Webflow stops every sync using it until you reconnect with a new token.