About Contentful
Iru reads spaces, content models, environments, and membership via the Content Management API (CMA) using a Personal Access Token (PAT) sent asAuthorization: Bearer. Do not use Content Delivery API (CDA) preview tokens - they lack management scope.
How It Works
| Detail | Value |
|---|---|
| Category | Headless CMS |
| Authentication | CMA personal access token |
Prerequisites
- Contentful user with access to the spaces you need for evidence.
Connect Contentful to Iru
- Contentful
- Iru Compliance
Complete this tab before you connect the source in Compliance.
Sign in to Contentful
Open the Contentful web app and sign in with a user who can access the spaces Iru should read.
Open Settings
Select Settings (gear or workspace settings, depending on your UI) for the organization or space that owns the token.
Open CMA tokens
Choose CMA tokens (Content Management API tokens) or the equivalent Personal access tokens screen.
Create a personal access token
Select Create personal access token (or Generate token). Enter a name such as Iru Compliance.
Set optional expiration
If Contentful offers expiration, set a date aligned with your key-rotation policy, or leave unset only if your security team allows non-expiring tokens.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
401 Unauthorized
401 Unauthorized
Expired PAT
Expired PAT
Rotate at Settings → CMA tokens, update Iru.
Missing spaces
Missing spaces
PAT inherits user membership - grant space access first.
Considerations
Revoke leaked tokens immediately and recreate: PUT…
Revoke leaked tokens immediately and recreate - PUT revoke endpoint documented by Contentful for automation.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
