Skip to main content

Update Arbor API authentication in Synergy Orchestra (password to token change)

Arbor is retiring non-expiring app passwords in favour of API tokens that must be rotated every 90 days. This article explains how to generate a new token and update the password in Synergy Orchestra.

Written by Dan Wilkins

Following recent communications from Arbor, the Arbor API is removing the use of non-expiring app passwords and enforcing the use of API tokens, which require rotation at least every 90 days. This guide covers the changes you need to make in the Arbor Developer Portal, and the related configuration change in Synergy Orchestra.

Arbor Developer Portal

This section is not intended to replace Arbor's own communication — it should be reviewed alongside Arbor's issued guidance on generating application tokens.

Your access to the Arbor API via Orchestra is governed via the Arbor Developer Portal. Your login to this portal is not the same as the app credentials used in Orchestra (or at least, it shouldn't be).

  1. Log in to the portal and navigate to App List via the Apps menu. You'll see your app, likely showing your council name and Synergy Orchestra.

  2. Click Details to open the App Details screen.

  3. Select MIS Application Tokens.

  4. Select Generate new token.

  5. Give the token a label (this can be anything, but we'd suggest naming it in line with your app name). Leave the scope as All schools. Leave the expiry as the default 90 days — it cannot be set higher. Select Generate token.

  6. The new token is displayed. This will not be shown again, so keep a secure copy before continuing.

Changing configuration in Orchestra

The new token needs to be set as the password for each Arbor school in your sources list. Because the token must be rotated at least every 90 days, the password in Orchestra must be updated after every rotation too.

To minimise ongoing effort, we recommend setting the token as the default password at the top-level 'sources' section in Orchestra Manager, then removing the individual password from every Arbor school in your source list. Orchestra will then use the default password automatically, meaning the password only needs changing in one place in Orchestra.

⚠ Only remove passwords from Arbor sources — do not modify sources for other MIS systems such as Bromcom, Integris, or ScholarPack.

Once a school's password is removed, the default value (if defined) will display in a greyed-out state, confirming it's inheriting the default.

Rotating the token and updating Orchestra

Within every 90-day period, the token must be rotated in the Arbor Developer Portal, or it will expire and you'll lose access to Arbor school data.

In the portal, go to App List > Details > MIS Application Tokens and select Rotate against your token entry. You'll be given a new token, which should then be used to update the password in Orchestra — against the default sources setting if you've used that approach, or against every individual Arbor school if not.

Did this answer your question?