Skip to content

API tokens and automation

3 min · Screen: /admin/api-tokens · Needs: Permissions.ApiTokens.Manage

  1. Open Admin › API tokens and click New token

  2. Describe What it is for and set Expires in (days, at most 365)

  3. Tick the permissions it may use

    Only API permissions you hold yourself are offered. The token is narrowed again at every request, so it never outlives your own rights.

  4. Issue the token and copy it now

    It is shown this once and cannot be retrieved.

Admin › API tokens - issue a token and see every token's scopes, expiry and last use
Admin › API tokens - issue a token and see every token’s scopes, expiry and last use
  • The list shows each token’s name, prefix, scopes, expiry, last used and state.
  • Revoke a token the moment it is no longer needed or may have leaked.
  • Use one token per system, so revoking one breaks nothing else.