About this question
API-only users cannot log in and choose 'Reset my security token'. Right now, in my company, we select a System Administrator profile for users, log in for the first time, choose 'Reset my security token', then change the profile to a custom profile that has API only enabled. The other way of doing it is, modifying the profile to not have API the only user checked initially and then turn it on once the security token is received. Is there a recommended way to do this? Is there an option to force the security token to be sent when the user is created with a profile that has API user enabled?