Connecting Kimai

ChronoFlow connects to Kimai using a personal API token. This gives ChronoFlow read access to your timesheets without needing your Kimai password.

Generating an API token

Log in to your Kimai instance and …

  1. Click your avatar in the top-right corner and choose API Access.
  2. Open the API Access tab.
  3. Click + Create, give it a name like ChronoFlow, setup an optional expiry date and copy the generated token. The token is shown only once - save it before navigating away.
  4. Make a note of the API URL - it will be needed later.
Kimai API token setup

Entering the token in ChronoFlow

  1. In ChronoFlow, go to Settings.
  2. Paste your Kimai base URL into the Kimai API URL field. Example: https://foobar.kimai.cloud/api.
  3. Paste your API token into the API Token field.
  4. Click Test Kimai Connection to validate the token.
  5. Click Save. ChronoFlow encrypts the token at rest using AES-256-GCM before storing it in the database.
ChronoFlow settings for Kimai

Required Kimai permissions

The API token needs read access to:

  • Timesheets
  • Projects
  • Activities
  • Customers

When using the Solo subscription, a standard Kimai user role has sufficient permissions.

When using the Team or Enterprise subscription, the API token needs the additional permission view_other_timesheet to access timesheets of other Kimai users.

You might also want to consider creating a dedicate Kimai role for ChronoFlow. See the Kimai documentation for more information.

© 2026 KloudShift GmbH . Alle Rechte vorbehalten.

Proudly streamlining your Kimai & Bexio workflow.