Maximo

 View Only

 How to generate Maximo Manage API Key programmatically in MAS 9.1 using API?

Hassan Ramadan's profile image
Hassan Ramadan posted 07/08/26 05:06 PM

Hello IBM Community,

I am working on an IBM Maximo Application Suite 9.1 environment with Maximo Manage.

In Maximo 7.6, we were able to generate an API token using:

POST /oslc/apitoken/create

with:

maxauth: Base64(username:password)

and:

{
  "expiration": -1
}

The response returned the Maximo API key, which could then be used for REST API calls.

However, in MAS 9.1, the same approach does not work.

Example:

POST https://<manage-url>/maximo/api/apitoken/create

Header:
maxauth: <base64(username:password)>

Body:
{
  "expiration": -1
}

returns:

{
    "reasonCode": "BMXAA7901E",
    "message": "BMXAA7901E - You cannot log in at this time. Contact the system administrator.",
    "statusCode": "403"
}

The same username/password works successfully when logging into Maximo Manage UI.

I tested:

GET /maximo/api/whoami?lean=1

with the same maxauth header and received the same 403 response.

However, when I manually create an API key from:

Manage Application
 -> Administration
    -> Integration
       -> API Keys

the generated API key works successfully for:

apikey: xxxxx

against Maximo REST APIs.

My requirement is:

  • Generate Manage API keys programmatically.
  • Revoke/rotate them through API.
  • Avoid requiring administrators to manually create API keys from the UI whenever a new integration user is created or recreated.

Is there an API available in MAS 9.1 to create Maximo Manage API Keys equivalent to /oslc/apitoken/create from Maximo 7.6?

What is the recommended IBM approach for applications that need dynamic user authentication and Maximo REST API access in MAS 9.1?

Maycon Belfort's profile image
Maycon Belfort IBM Champions

Hi @Hassan Ramadan,


What changed in MAS 9.1 is that the old MAXAUTH path you used in Maximo 7.6 is no longer the supported way to authenticate to Manage. In MAS/Manage, only OIDC/SAML and apikey are supported, and maxauth is not supported in Maximo Manage.

For your requirement, I would try to manage Manage API keys through the MXAPIAPIKEY object structure, with a generated Admin API KEY that you can re-use across your Key management lifecycle.

A few examples you can test.

Create an API KEY for a user:

POST /api/os/mxapiapikey

Body:

{"expiration": -1,"userid": "WILSON"}

List all API Keys:

GET /api/os/mxapiapikey

Delete an API Key:

DELETE /oslc/os/mxapiapikey/{id}


Example:

curl -k -X POST "$MAXIMO_HOST/api/os/mxapiapikey" \
  -H "Content-Type: application/json" \
  -H "apikey: <admin_apikey>" \
  -d '{
    "userid": "INTUSER1",
    "expiration": 90
  }'

IBM documentation: https://www.ibm.com/docs/en/masv-and-l/maximo-manage/cd?topic=apis-api-keys

Hassan Ramadan's profile image
Hassan Ramadan

Hi @Maycon Belfort,

Thank you for your clear explanation and for confirming that maxauth is no longer supported in Maximo Manage under MAS 9.1.

Using MXAPIAPIKEY with an Admin API key for the API key lifecycle makes sense for creating, listing, and deleting Manage API keys.

I have one follow-up question regarding the user authentication flow.

In Maximo 7.6, we used to validate the user credentials by calling Maximo APIs with:

maxauth: base64(username:password)

Before generating the API token.

Since maxauth is not supported anymore in MAS Manage, what is the recommended supported approach to validate an interactive user's credentials before creating a Manage API key for that user through MXAPIAPIKEY?

Should the credential validation be done only through MAS OIDC/SAML authentication flow, or is there any supported MAS/Manage REST endpoint that can validate username/password credentials?

Our goal is to allow a custom application to authenticate users and then generate/revoke their Manage API keys programmatically without manual intervention from the Maximo UI.

Thanks again for your support.