Basic Auth with a user that has API access + VIEWER on the budget. Shares the 100-call-per-minute rate limit with the REST API.
Authentication
The BI Export API uses Basic Authentication. Provide the user's email and local password in the standard Authorization: Basic header.
The authenticating user must have:
- API access enabled on the user record.
- At least VIEWER permission on the budget being exported.
If either is missing, calls return HTTP 403 (or an empty payload for some endpoints).
The integration-user pattern
Most teams create a dedicated integration user (e.g. customer.integrations@example.com) for API work rather than reusing a human user's credentials. The integration user:
- Has API access enabled.
- Has a long-lived local password managed securely on the integration side.
- Is granted VIEWER (or higher) on every budget the integration needs to read.
For how to set this up, see Does my SSO user need a separate password to use the Allocadia API?
Rate limits
The BI Export API shares the 100 calls per minute per user rate limit with the Allocadia REST API. Exceeding the limit returns HTTP 429 Too Many Requests.
Because BI Export calls return large payloads and can take seconds to complete, it's unusual to hit the rate limit on this API alone — but if your integration shares a user between BI Export and REST API calls, the combined traffic counts against the single budget.
For guidance on backing off and reducing call volume, see Allocadia API requests returning HTTP 429 — too many requests.
Async-endpoint timing
The all.zip endpoint can take seconds to minutes depending on data size. Polling intervals shorter than 5–10 seconds offer no benefit — the job runs on a server-side cadence. Use the callback URL pattern instead if your integration can accept pushed completion events.
Comments
Please sign in to leave a comment.