Use a read-only token or a custom token with only the read scopes needed for the data.
Before you start
- A read-only Mercury API token for Production or Test account.
1. Open Mercury API settings
In Mercury, open Settings → API Tokens.
2. Create a read-only token
Create a read-only token, or a custom token with only read scopes. Copy it.
Select a read-only token
Mercury offers read-only, read/write, and custom API tokens. Use read-only for Permute, or a custom token limited to the read access you need. A read/write token can initiate transactions or manage recipients, which the connection does not require.
Choose Production for a real account or Test account for a test token in Permute. The environment and token must match.
Save and protect the token
Mercury shows a generated token once. Copy it before closing the dialog and paste it into Permute’s API Key field. Do not save it in source control or send it in a message.
If a token is exposed, revoke it in Mercury and create a new one. A lost token must also be replaced because Mercury will not display it again.
3. Add Mercury in Permute
In your workspace, open Connectors, select Add Connector, choose Mercury, and name the account.
Under Sync which data?, choose an option:
| Choice | What it does |
|---|---|
| Everything | Selects all discovered data available to this connection. |
| Select manually | Choose the tables Permute syncs. |
- Choose Production for real data or Test account for a sandbox token.
- Paste the matching token into API Key and select Connect.
4. Choose tables (manual selection)
If you chose Select manually, open the connector after connecting. Use the checkboxes to select at least one table, then select Save selection.
5. Check the first result
- Choose a known Mercury account or transaction in the selected environment.
- For a custom token, confirm its read permissions cover that group.
Available data
| Data group | What the setup screen covers |
|---|---|
| Banking | Banking and transaction data. |
| Other products | Card, credit, and treasury data. |
Keep test and production apart
Permute has Production and Test account choices for Mercury. Use a token made in the corresponding Mercury environment. A working test connection only shows test-account data; it does not prove access to live banking records.
Pick one known account or transaction in the chosen environment and compare it after connecting. If the token is accepted but the record belongs to the other environment, return to the environment choice and token source before changing table selection.
Access and source details
Recover from a lost token
Mercury does not reveal a token again after its creation dialog closes. Create a new token in the right Production or Test account and revoke the old token if it is no longer needed.
Do not store the token in a public file. Mercury warns that anyone with the token can use its assigned API privileges.
Troubleshooting
| Problem | What to check |
|---|---|
| The token is rejected | Check that it belongs to the selected Production or Test account. |
| One group is absent | Check the custom token’s read permissions for that group. |