New in IT Portal 4.6.41 · Q4 2026
Overview
Everyone wants to point an AI assistant at their documentation. Ask Copilot or ChatGPT "what is the firewall at this client?" and get an answer from IT Portal. The catch has always been access: until now, connecting anything to the API meant an organization-wide key that could see far more than the person asking the question.
IT Portal 4.6.41 fixes that. Users can now connect scripts, automation and AI assistants (through MCP connectors) to IT Portal as themselves. Every request only sees what that person can see in the portal — the same companies, the same object permissions, the same rights to add, edit or delete. Never more.
How it works
There are three ways to connect, and your administrators choose which ones to allow:
- Personal API keys. A user creates a key under My Settings and pastes it into their app or script. A Copy instructions button hands an AI assistant or developer everything it needs to connect.
- Browser sign-in. The app opens IT Portal in the browser, the user signs in as usual — MFA and single sign-on included — and clicks Approve. No key is ever shown or pasted.
- Microsoft Entra sign-in. For teams on Microsoft 365, a connector that already signs people in with Microsoft Entra can exchange that sign-in for IT Portal access. No keys to manage at all.
Whichever route is used, access follows the person in real time. Disable a user, move them out of a company, or remove a permission, and their keys and connected apps follow on the very next request.
You stay in control
User API access is off by default. Nothing changes until an administrator turns it on under Admin Settings → Security → API Keys. From there you decide:
- Who can create keys — everyone, or only members of a security group.
- How far any key can ever reach — for example read-only, no passwords, or every company except a sensitive few.
- How long keys last, and when unused keys expire on their own.
- Which sign-in methods are allowed — personal keys, browser sign-in, Microsoft Entra, or any mix.
A single screen lists every personal key and connected app across the portal, with a full activity log and one-click revoke.
Why it matters
- AI without over-sharing. The assistant works as the person asking, so it can only answer with what they are already allowed to see.
- No more shared all-access keys. Every action is attributed to a real user, which makes auditing simple.
- Fits how your team already signs in. Browser and Microsoft Entra sign-in keep MFA and single sign-on in the loop.
Better organization keys, too
Organization-wide API keys gain two new options: all companies except and all resources except. Fence off a handful of sensitive companies, or keep passwords out of an integration entirely, and anything you add later is covered automatically.
Getting started
An administrator enables user API access under Admin Settings → Security → API Keys → User API Keys. Users then create keys or approve connected apps from My Settings → API Keys. The full setup, including Microsoft Entra configuration, is in our knowledge base: Personal (User) API Keys, Browser Sign-In and Microsoft Entra API Access.
Personal API keys are part of IT Portal 4.6.41, our Q4 2026 release.

