Skip to main content
POST
The token in the response is never revealed again. Store this somewhere safe, and never share or commit it to source control.
Unrestricted (cross-org) tokens are deprecated and will be removed in a future release. Always include at least organization in the request body.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

tokenName
string
required

The name of the api token.

Body

application/json

Optional restriction for the token. Omit the body for an unrestricted token, pass organization alone for an org-scoped token, or pass organization + group + scopes for a group-scoped token.

organization
string

The organization slug to restrict this token to. Required when group is set.

Example:

"my-org"

group
string

The group name (inside organization) to restrict this token to. Requires organization and a non-empty scopes list.

Example:

"default"

scopes
enum<string>[]

Permissions to grant a group-scoped token. Each entry is either an individual scope or one of the presets read-only (expands to read) and full-access (expands to every scope). Required and must be non-empty when group is set. db:mint-token lets the token issue new SQL credentials; db:rotate-creds invalidates every existing SQL token for the database — they are deliberately separate because rotation is destructive.

Available options:
read,
db:create,
db:delete,
db:configure,
db:mint-token,
db:rotate-creds,
group:configure,
group:mint-token,
group:rotate-creds,
read-only,
full-access
Example:

Response

200 - application/json

Successful response

name
any
id
any
token
string

The actual token contents as a JWT. This is used with the Bearer header, see Authentication for more details. This token is never revealed again.

Example:

"..."