We need a supported way to enable a service identity to retrieve fax metadata across users via the XM Fax SOAP API. Specifically, we need read-only access to operations such as
Find Outbound Faxes, Find Inbound Faxes, Find Outgoing Faxes, Get Outbound Fax Advanced, Get Inbound Fax Advanced, Get Audit Logs, Get Accessible Fax Boxes
This access should allow querying metadata only (timestamps, status, sender/recipient, failure reasons).
No fax content or attachments are required.
If XMedius’ recommended approach is to use a dedicated service account, configure delegation, or issue a user-scoped token, we are happy to follow that model.
Alternatively, if there is a supported reporting or usage API that provides this data, we are open to using that instead.Why we need it. The current enterprise access token works for User directory operations (e.g., get User Profile)Send Secure REST APIs However, all per-user fax data operations return: 401 - No permission / Invalid Permission. This suggests these operations require either user-scoped access or additional permissions beyond the enterprise token. Security / compliance Read-only access only (no send/modify capabilities)Strict allow list enforced in integration code. All API calls are audit-logged Token securely stored (AES-256-GCM) No fax content stored - metadata only Environment context Enterprise: rfbcu Hosts:faxus1.xmedius.com (XM Fax SOAP)sendsecure.xmedius.com (Send Secure REST)XM Fax version observed: 26.2.1.209 Web Services API version: v14Current token type: enterprise access token Created via: /enterprises/rbfcu/access_tokens/new Failing operations: All findFaxes, get*FaxAdvanced, getAuditLogs, getAccessibleFaxBoxes> SOAP fault 401 "Invalid Permission"
Product:Other