Skip to main content

About Contentful

Iru reads spaces, content models, environments, and membership via the Content Management API (CMA) using a Personal Access Token (PAT) sent as Authorization: Bearer. Do not use Content Delivery API (CDA) preview tokens - they lack management scope.

How It Works

Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN
DetailValue
CategoryHeadless CMS
AuthenticationCMA personal access token
Official references: Authentication, Personal access tokens, CMA reference.

Prerequisites

  • Contentful user with access to the spaces you need for evidence.

Connect Contentful to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Contentful

Open the Contentful web app and sign in with a user who can access the spaces Iru should read.
2

Open Settings

Select Settings (gear or workspace settings, depending on your UI) for the organization or space that owns the token.
3

Open CMA tokens

Choose CMA tokens (Content Management API tokens) or the equivalent Personal access tokens screen.
4

Create a personal access token

Select Create personal access token (or Generate token). Enter a name such as Iru Compliance.
5

Set optional expiration

If Contentful offers expiration, set a date aligned with your key-rotation policy, or leave unset only if your security team allows non-expiring tokens.
6

Generate and copy the token

Generate the token and copy the value once. Store it securely; you will paste it into Iru as the Bearer token.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
PAT not CDA token; paste exact string.
Rotate at SettingsCMA tokens, update Iru.
PAT inherits user membership - grant space access first.

Considerations

Revoke leaked tokens immediately and recreate: PUT…

Revoke leaked tokens immediately and recreate - PUT revoke endpoint documented by Contentful for automation.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.