Skip to main content

About Aha! Ideas

Iru calls the Aha! REST API with Authorization: Bearer using a personal API key. Keys inherit the creating user’s product permissions - prefer a service account so churn does not break compliance sync.

How It Works

Authorization: Bearer YOUR_API_KEY
DetailValue
CategoryProduct management
AuthenticationBearer (account API key)
Host pattern: https://YOUR_SUBDOMAIN.aha.io. Official references: API keys (swap subdomain), API reference.

Prerequisites

  • User with access to the products you must evidence (often Owner, Administrator, or Reviewer).
  • Your subdomain (acme from https://acme.aha.io).

Connect Aha! to Iru

Complete this tab before you connect the source in Compliance.
1

Open your Aha! profile menu

In Aha!, click your avatar (profile menu) in the product chrome.
2

Open personal settings

Choose Settings, then open the Personal section (or equivalent) so you are editing your own account, not only a single product.
3

Open Developer and API keys

Select Developer (or Developer settings), then API keys (labels can vary slightly by Aha! edition).
4

Generate a new API key

Select Generate API key (or Create API key). Enter a name you will recognize later, such as Iru Compliance.
5

Copy and store the key

Copy the key value once when Aha! shows it and store it in your vault. You will paste it into Iru as the Bearer token; you typically cannot view the same secret again after you leave the page.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
User deactivated or key deleted - regenerate from active service account.
Wrong subdomain string.
Issuing user lacks workspace access - adjust Aha! membership or key owner.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.