# System API Settings

> Settings of one system API of API Maker - open it over HTTP with TOKEN_ACCESS or IS_PUBLIC, require person tokens with authProviders, cache its answers, refuse plain payloads.

Source: https://docs.apimaker.dev/v1/docs/settings/systemApiSettings.html

Each [system API](https://docs.apimaker.dev/v1/docs/apis-all/overview.html#system-apis) has its own settings. Without settings, a system API is `NO_ACCESS` : your code calls it through `g.sys`, the admin panel tests it, and an HTTP call is refused with `401`. The token API is the exception : public unless its settings say otherwise.

| | |
|---|---|
| Page | `API Info → System API` → the plus button of the API. |
| Type | `T.ISystemApiSettingsTypes` |
| Default | `NO_ACCESS` for every system API but the token API. |

**Open the hash data API to the applications**

```typescript
import * as T from 'types';

let systemApi: T.ISystemApiSettingsTypes = {
    enableCaching: false,
    acceptOnlyEncryptedData: false,
    apiAccessType: T.EAPIAccessType.TOKEN_ACCESS,
    // authProviders: ['users_tg'],
};
module.exports = systemApi;
```

## The keys

| Key | Values | Meaning |
|---|---|---|
| `apiAccessType` | `NO_ACCESS` (default), `TOKEN_ACCESS`, `IS_PUBLIC` | Who may call it over HTTP : nobody, an API user whose group grants the system API, anybody. |
| `authProviders` | names of [auth providers](https://docs.apimaker.dev/v1/docs/authorization/AMDB.html) | The person tokens the call must carry. Absent : `common.authProviders` of the secret. `[]` : the API user token alone. |
| `enableCaching` | `true` / `false` | Cache the answers in Redis. Reset them with [reset system API cache](https://docs.apimaker.dev/v1/docs/apis-all/system-apis/system-generated-reset-redis-cache-system-api.html). |
| `acceptOnlyEncryptedData` | `true` / `false` | Refuse plain bodies : [encrypted payloads](https://docs.apimaker.dev/v1/docs/features/security-features.html#encrypted-request-payloads). |

- Open only what applications really need : execute plain query, get secret, create indexes and the cache resets change or reveal a lot. The [APIs Security Report](https://docs.apimaker.dev/v1/docs/apis-security/api-security-report.html) lists the sensitive ones which are open.

## Related

- [All system APIs](https://docs.apimaker.dev/v1/docs/apis-all/overview.html#system-apis) · [System APIs from code](https://docs.apimaker.dev/v1/examples/sys/system/system.html)
