# Raynet CRM: connecting

The assistant reads from Raynet who is writing to it: the contact and the
company, business cases, offers and orders, and activities. It never writes to
Raynet. What exactly it may read, you decide for each mailbox separately. How
connections work in draften in general is described on the
[Integrations](/en/admin/integrations) page.

## What you need

- Raynet on the **PROFESSIONAL** plan or higher — the START plan has no API
  keys.
- An instance on **app.raynet.cz** (the Czech server). Instances on Raynet's
  Slovak or international servers (`app.raynetcrm.sk`, `eu.raynetcrm.com`,
  `app.raynetcrm.com`) cannot be connected.
- A **Raynet administrator** — only they can create the user and the API key.
- In draften, an **owner or manager of the organisation**.

## In Raynet

Raynet has no read-only key: an API key always has the rights of the user it
belongs to. That is why you make a **separate user with a read-only role** for
the assistant. Do not give it an administrator's key — an administrator sees
and may do everything.

### A read-only user

1. At the top right, click your name → **Nastavení** (Settings).
2. In the menu on the left, open **Uživatelské účty** (User accounts) and add
   a user (**Přidat uživatele** (Add user); in the paid version first **Přidat
   další uživatelské účty** (Add more user accounts) and then **Přiřadit
   uživatele** (Assign user)). Fill in:
   - a name, for example `draften`,
   - the login e-mail — note it down, draften will need it,
   - the role **Jen ke čtení** (Read only).

   Every user is a paid licence in Raynet.
3. If the user already exists: **Uživatelské účty** → open their profile →
   **Oprávnění uživatele** (User permissions) → change the role to **Jen ke
   čtení** and save.
4. Optionally, limit which records the user sees: **Nastavení** →
   **Bezpečnostní úrovně** (Security levels) → **Přidat úroveň** (Add level),
   name it and choose the user.

### API key

1. **Nastavení** → in the menu on the left, in the **PRO VÝVOJÁŘE** (For
   developers) part → **API klíče** (API keys).
2. Click **Nový API klíč** (New API key). In the **Vytvořit API klíč** (Create
   API key) window, fill in:
   - **Název klíče** (Key name) — for example `draften`,
   - **Uživatel** (User) — the read-only user from the previous step. The key
     will read with their permissions.
3. **Copy the key straight away** — once it is saved, Raynet never shows it
   again. Then click **Vytvořit API klíč**.

### Instance name

At the top right, click your name → **O aplikaci Raynet CRM** (About Raynet
CRM); the **instance name** is there. It is also the part of the address after
`app.raynet.cz/` — for the address `https://app.raynet.cz/firma` it is `firma`.

## In draften

1. Open Organisation → **Integrations** and, in the **Integrations** card,
   fill in:
   - **System** — **Raynet CRM**,
   - **Name** — for example `Raynet - sales`,
   - **Instance name** — from the previous step,
   - **User (e-mail)** — the login e-mail of the read-only user,
   - **Access secret** — the API key.

   Click **Add connection**. The key is stored encrypted and never shown
   again.
2. In the connection's row, open the **⋯** menu → **Test the connection**. In
   a moment it shows "Connection fine (…), account …". When the user may not
   read something, the test lists it under "Not available with this token:".
3. In the **Which mailboxes may use the connection** part, click **Grant** by
   a mailbox, tick what the assistant may read and click **Save the grant**:
   - **Contact and company**,
   - **Business cases** and, under it, **Amounts**,
   - **Offers and orders**,
   - **Activities** and, under it, **Description and solution of
     activities**.
4. The assistant's editor then adds, in the assistant's Settings →
   **Knowledge**, a source of the **external system** kind and chooses what
   the assistant really reads — see
   [Connecting a CRM and other systems](/en/connecting-a-crm).

When you replace the key, paste the new one into **New access secret** by the
connection and click **Replace**; then **Test the connection** again.

## Connection test errors

The test's message is in English, straight from Raynet or from draften:

| In the message | What it means | What to do |
|---|---|---|
| `the user name or the API key was refused (401)` | Raynet did not accept the e-mail or the key | check that the e-mail is the login e-mail of the user the key belongs to, and paste the key again |
| `the user of the API key may not read this (403)` | the key's user may not read | check the user's role and security level |
| `Raynet rate limit reached (429)` | the daily API call limit is used up | try later; Raynet sets the limit by plan |
| `Raynet needs the instance name (letters, digits, dashes)` | the instance name is missing or has invalid characters | copy the instance name from **O aplikaci Raynet CRM** |
| `Raynet answered HTTP …` | another answer from Raynet | check the instance name and try again |
