Using Practice Engine's API for Writing Data and Setting Up Credentials

Overview

Practice Engine provides robust API capabilities that allow users to interact programmatically with the system, including creating and updating records when the API user has the necessary permissions. This article explains what the Practice Engine API can and cannot do, how to set up API credentials, how to access the API documentation, and how to identify the correct API calls to use. Use this guidance when integrating Practice Engine with external systems such as CRMs, reporting tools, or other business applications.

Overview of Practice Engine's API Capabilities

The Practice Engine API enables external applications to perform actions similar to those available in the frontend interface. Key points to understand:

  • Direct database access provided to customers (for example, for engine_client and PEwarehouse_client) is read-only, which is suitable for reporting tools such as Power BI.

  • The API can be used to both read and write data — including creating and updating clients, contacts, and other records — when the API user has the appropriate frontend permissions.

  • API calls apply the same security and permission rules as the frontend, so an API user can only perform actions their assigned role allows.

  • Customers can build their own API integrations. Developer time from Practice Engine is available on a billable basis if additional assistance is needed.

This makes it possible to integrate Practice Engine with external systems — for example, using a CRM as the source of truth for clients and contacts and pushing new records into Practice Engine when an engagement letter is signed.

Setting Up API Credentials and Permissions

To use the API, set up a dedicated API user in Practice Engine and generate authentication credentials. Follow these steps:

Step 1 — Create an API User

  1. Log in to Practice Engine

  2. Create a staff user that will serve as the API user.

  3. Assign the required permissions to this user based on the actions the API will perform. The API user should have only the permissions necessary for its role to minimize security risk.

Step 2 — Generate the App ID and App Key

  1. Navigate to Admin > Taskpad > API Authentication Administration

  2. Generate the App ID and App Key for the API user. These credentials are required to authenticate API requests.

  3. Store the App ID and App Key securely. Treat them as sensitive credentials.

Step 3 — Access the API Documentation

  1. On the API Authentication Administration page, select View Instructions

  2. Follow the link to the Swagger Help documentation, which lists all available API calls and their details.

  3. Review the documentation to identify the endpoints needed for the intended integration.

Identifying the Correct API Call

When determining which API call to use for a specific action, the browser's developer tools can be used to trace what the frontend does and mirror it in your API integration.

  1. Open the browser's developer tools.

  2. In Practice Engine, perform the action on the frontend that matches what the API integration will do.

  3. In the Network tab, locate the relevant request associated with that action.

  4. Review the Headers tab and copy the Request URL to identify the API endpoint being called.

  5. Review the Payload, Preview, and Response sections to see the request body and expected response.

  6. Use this information as a reference when building the same API call in Postman or another API client.

Security Considerations

  • Grant the API user only the permissions required for its role — avoid using an over-privileged user for automation.

  • Keep the App ID and App Key confidential; do not embed them in client-side code or share them outside of secure channels.

  • Rotate credentials periodically or if a leak is suspected.

  • Monitor API usage — excessive or poorly optimized calls can affect Practice Engine performance.

Performance Considerations

Practice Engine allows customers a high degree of freedom to use APIs with their environment. However, API activity can affect system performance if it is overused or poorly designed. When building an integration:

  • Batch operations where possible instead of making many individual calls.

  • Avoid high-frequency polling; use targeted calls tied to specific events (for example, when an engagement letter is signed).

  • Test integrations in a non-production environment before enabling them in production.

When to Engage Practice Engine Developer Support

Customers can build API integrations on their own, but Practice Engine developer time is available for additional assistance:

  • For general questions about a specific API call or approach, contact Support and, if needed, the request can be routed to a developer for a quick answer.

  • For custom development or integration work, developer time is available on a billable basis.

Related Topics

  • API Authentication Best Practices

  • Integrating External Systems with Practice Engine

Key Takeaways

  • Direct database access provided to customers is read-only; the API is the supported path for writing data to Practice Engine.

  • API actions are governed by the same permissions as the frontend, based on the API user's role.

  • API credentials (App ID and App Key) are generated under Admin > Taskpad > API Authentication Administration.

  • The Swagger Help documentation, accessed via View Instructions, lists all available API calls.

  • Browser developer tools can be used to identify the exact API call behind any frontend action.

  • Customers can build their own API integrations; Practice Engine developer time is available on a billable basis for additional support.