To use the XML API, you must provide the logon credentials of a user with the Use XML API permission granted. recommends you to create a dedicated user for this purpose.
On the Permissions page, select Users, then Create New User to add a user.
Assign the new user Xml api permissions only.
The Xml api and the related sub-permissions are added to the Selected permissions list.
The administrator can assign selected sub-permissions, rather than all Xml api permissions.
The XML API uses a Representational State Transfer (REST) format for request response processing. The XML REST API receives requests through standardized HTTP GET/POST parameters and the response is an XML response.