> For the complete documentation index, see [llms.txt](https://docs.whalesync.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.whalesync.com/connectors/webflow/site-api-tokens.md).

# Connect with a site API token

Connect Webflow with a site API token instead of signing in. The six permissions the token needs, why it reaches one site, and how to fix token errors.

Signing in to Webflow is the default way to connect it to Whalesync. A site API token is an alternative if you prefer not to sign in, or are setting up a sync through the [API](https://docs.whalesync.com/api/reference.md) or [MCP server](https://docs.whalesync.com/api/mcp.md) and need a credential to hand over.

A token differs from signing in in three ways:

* It does not expire.
* It reaches only the site it was generated in.
* It can be pasted into the API or given to an agent. A sign-in has to happen in a browser.

## Generate the token

1. In Webflow, open the site and go to **Site settings** > **Apps & integrations**.
2. Under **API access**, click **Generate API token**.
3. Name it `Whalesync`.
4. Give it every permission listed below.
5. Generate the token and copy it. Webflow shows it only once.

### Permissions

All six are required. Set each to read and write, except **Authorized user**, which is read-only.

| Permission | Why Whalesync needs it |
| --- | --- |
| CMS | Read and write the items in your collections. |
| Sites | Read your site, and publish it when a sync asks to. |
| Pages | Read and update your site's pages. |
| Ecommerce | Sync products and SKUs. |
| Users | Whalesync's sign-in asks for it too. It was for syncing site users, which Webflow retired with [Memberships](https://docs.whalesync.com/connectors/webflow/webflow-memberships-sync.md). |
| Authorized user | Read the account the token belongs to. |

## One site per token

A token reaches only the site it was generated in, so a connection made with a token syncs that one site. To sync another site, create a connection with a token from that site.

Reauthorizing with a token from a different site is refused. Use a token generated in the site the connection syncs.

## Paste the token into Whalesync

1. In the connect step, choose **Use a site API token instead**.
2. Paste the token and click **Authorize**.
3. Pick the site.

A connection keeps its method. To switch between token and sign-in, create a new connection.

## Errors

| Message | What to do |
| --- | --- |
| Webflow did not accept this site API token | The token was copied wrong or deleted from the site settings. Copy it again, or generate a new one. |
| This site API token is missing a permission Whalesync needs | Generate a new token with all six permissions above. |
| This site API token does not have access to a site this connection syncs | The token is from another site. The message ends with the ID of the site the connection syncs, in parentheses; generate a token in that site. |

## Revoking the token

Deleting the token in Webflow stops every sync using it until you [reconnect](https://docs.whalesync.com/resources/support/reconnecting-a-sync.md) with a new token.
