Skip to content

API tokens

An API token lets a script, a pipeline or another system call the Xovris API for your workspace. Create one in the command centre under Settings, Developers.

  • A name of 1 to 100 characters, so you know later what uses it.
  • Scopes: read, or read and write. Ask for read unless the caller changes something.
  • An expiry between 1 and 365 days, 90 when you do not choose. Tokens that never expire are not issued.
  • Its remaining life shown as a meter beside it, so a token close to its end is easy to spot.

The token’s secret is shown once, when it is created. Store it in your secret manager straight away.

POST /v1/tokens
Content-Type: application/json
{"name": "Deploy pipeline", "scopes": ["read"], "expiresInDays": 90}

An expiry outside 1 to 365 days, or a scope other than read and write, is refused with the reason and what to send instead.

Revoke it from Settings, Developers. A revoked or expired token is refused on its next call.