FAQ:Understanding New SmartThings Integration Method (Draft of updates)
New SmartThings Integration Method:
This new method is designed to significantly simplify the integration process, especially for customers who already manage multiple SmartThings accounts with a large number of existing devices.
Unpair and re-pairing a customer's entire smart home setup is impractical and time-consuming. Instead, the new approach focuses on efficiency and convenience.
No Re-pairing Required: Secure method to generate fresh tokens for the existing SmartThings accounts. This eliminates the need for you to unpair and then re-pair all customers' devices to the new SmartThings account.
Direct Lock Onboarding: This allows us to onboard your locks directly to our platform, leveraging your current SmartThings configuration. This article will guide you step-by-step through the process of using this new, streamlined method for your lock onboarding.
Frequently Asked Questions about Understanding New SmartThings Integration
What is the main reason Lynx introduced this new token process for SmartThings?
Answer:
The primary reason is to improve Customer Experience and Operational Efficiency. This new method allows us to onboard a new lock directly from a customer's existing, active SmartThings account without forcing the customer to unpair and re-pair every single device in their entire SmartThings ecosystem. This prevents major customer disruption during integration.
Question 2:
Why did SmartThings make this change to their tokens?
Answer:
SmartThings implemented this as a security upgrade to align with modern API practices. They are deprecating the old tokens due to their broad, long-lived access, which posed a high security risk. The new system limits the token's lifespan to 24 hours and scope to increase overall platform security.
Question 3:
What is the difference between the Old and New SmartThings tokens?
Answer:
Features
Old Token (Main account level token)
New Token (Location token)
Platform Validity
Permanent (Long-Lived).
24 HOURS (Mandatory Time-to-Live for all newly created PATs).
Token Generation
One-time creation.
New Token must be generated for each onboarding request.
Scope
Account-Level (Broad Access)
Location-Based (Targeted to one property)
Tech Ticket Required
NO. Onboarding of new devices was often automatic or done through direct pairing.
YES. The token and lock details must be submitted in a Tech Ticket immediately for the Tech Team to use the short-lived key.
New Device Onboarding
No need to generate a new token.
Requires generating a fresh 24-hour token.
Question 4:
How is the New Token generated, and what steps must be completed immediately after creating it?
Answer:
The token is a Personal Access Token (PAT) created by the Support team, intended for one-time use:
1. Generation: We need to click the SmartThings link, log in, select all permission checkboxes, and name the token using today's date 2. Immediate Copy: We must immediately copy the token as it will not be visible again.
3. Lynx Action: The token, the property name, and the lock name must be shared with the Tech Team to create an urgent Tech Ticket for syncing integration from the backend.
Question 5:
What happens if the 24-hour token expires before the lock is onboarded?
Answer:
The token becomes invalid, and the Team receives a 401 Unauthorized error upon attempting to fetch the lock details.
Resolution: A fresh token and a new Tech Ticket must be created. The onboarding team loses precious time if this deadline is missed.
Question 6:
Does this new 24-hour token change impact existing, already-onboarded locks?
Answer:
NO, there is NO impact on existing locks. The core functionality for already-onboarded locks is stable because:
The existing locks were integrated using a different token flow.
The Lynx backend system is designed to automatically regenerate the necessary access tokens for these ongoing integrations. This new 24-hour rule applies only to the initial connection of a new lock.
Question 7:
If a lock needs to be onboarded, is the new token always required?
Answer:
YES. Every time a new lock or property needs to be onboarded or synced to the Lynx system, a new, fresh 24-hour PAT must be generated by the customer to start the process.
Question 8:
What is the official website link for generating the New SmartThings Token?
Once you are logged in to the SmartThings Account, click on this button.
After that, enter Today's Date as the name, so that we can easily track when the last API Token was generated.
Check all the dialogue boxes till the bottom of the page, and click on Generate Token.
After that, you'll be able to see your token. Kindly copy this Token carefully, as once this window is closed, you'll not be able to see this again.
After a token is generated, the lock details and the new token must be shared with the Tech Team. We will create a Tech Ticket for this purpose, enabling the tech team to fetch the lock from Samsung SmartThings and add it under the ST Integration in Lynx.
You can simply view this Tech Ticket to get the correct format of this kind of Tech Ticket.
If the customer wants to onboard a second new lock next week, do they need a new token?
Answer:
YES. For any new lock onboarding, a fresh 24-hour token must be generated by the customer, and a new Tech Ticket created. The single-use nature of this temporary token is a mandatory security requirement from SmartThings.
Question 11:
How can I set up my account to add future properties without generating a new 24-hour token every time?
Answer:
You can streamline your future onboarding process and bypass the 24-hour token limit by pre-registering multiple empty placeholder locations during your initial setup. Since the SmartThings Personal Access Token is only valid for 24 hours for establishing new connections, creating extra locations labeled as Location 1 or Future Property 2 while the token is active ensures they are permanently linked to your Lynx account right from the start.
When you are ready to onboard a new property weeks or months later, you simply select one of these pre-authorized empty locations in your SmartThings app, rename it to your actual property name, and pair your hub and devices to it. Because the location ID was already authorized during the initial setup, Lynx will instantly recognize the devices without requiring you to generate a new security token or re-authorize the integration.
Question 12:
What is the SmartThings Token Expiry Column, and why was it introduced?
Answer:
Previously, if a SmartThings authorization token expired, the connection status could still display as "Authorized," making it difficult to diagnose why smart devices stopped communicating. The Token Expiry Column adds dedicated visibility into authorization token expiration dates directly within the Lynx portal, and updates the Authorization Status automatically once a token expires — eliminating false "Authorized" readings caused by outdated tokens.
Question 13:
How does Lynx keep the Authorization Status accurate over time?
Answer:
The workflow operates seamlessly in the background:
1. Authorization Date Tracking: Whenever a SmartThings account is linked or re-authorized, the Lynx portal records and displays the official expiration date alongside the Authorization Status. 2. Automated Status Monitoring: The Lynx portal runs automated background checks to audit token expiration dates against the current date. 3. Automatic Status Refresh: If the expiration date has passed, the Lynx portal automatically updates the displayed connection status from "Authorized" to "Not Authorized."
Question 14:
Where can I view the Token Expiry Date for an integration?
Answer:
You can Token Expiry Date directly on the integrations page, alongside the Authorization Status, making account health clear at a glance.
Question 15:
Why did my SmartThings integration's Authorization Status change to "Not Authorized" on its own?
Answer:
This is expected behavior, not an error. The Lynx portal automatically updates the Authorization Status as soon as the vendor token expires, so customers are aware that re-authorization is required.
Question 16:
How do I fix an integration that shows "Not Authorized"?
Answer:
When a connection marked "Not Authorized" appears, admins simply click to re-authorize the integration, which instantly generates a new, active token.
Question 17:
I re-authorized my integration, but it still shows "Not Authorized" — what should I check?
Answer:
Check the Token Expiry Date column. If the date shown is still in the past, the re-authorization attempt on the SmartThings vendor side did not complete successfully and must be retried.
Important Notes:Standard Terminology: When discussing this feature with customers, always use "Token Expiry Date," "Authorization Status," and "Re-authorize Integration." Avoid backend terms like "database column," "cron job," or "token schema."
Troubleshooting Tip: If a customer claims they completed the re-authorization process but the connection still shows "Not Authorized," check the Token Expiry Date column. If the date shown is still in the past, the re-authorization attempt on the SmartThings vendor side did not complete successfully and must be retried.
Comments
0 comments
Article is closed for comments.