public-api-tokens

Admin-only viewset for managing public-API tokens (SystemUser + ResourceAccess rows).

Supports create, list, retrieve, revoke, and editing resource grants.

POST /public-api-tokens/ creates a new SystemUser for the caller's organisation, persists the requested ResourceAccess rows, and returns the plaintext token once. The token is never recoverable after this response.

GET /public-api-tokens/ lists the caller's org tokens without secrets. GET /public-api-tokens/{id}/ retrieves a single token without secrets.

Every route here selects its organization with X-Organization-Id, on the terms the header is documented with everywhere else: optional for a caller with one active membership, required (400) for a caller with two or more, and 403 when it names an organization the caller is not an active member of.

get/public-api-tokens/{id}/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

idstring required

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Response

idinteger required
integration_namestring required
is_activeboolean required

Indicates if the user is active.

available_resourcesstring[] required

Return a list of resource_name values from the prefetched ResourceAccess rows.

scoped_to_userinteger nullable required

Return the owner's User id from the denormalized membership column, or None.

scoped_to_membership_user_id is a concrete column already storing the membership's user_id, so the value is returned directly with no extra query.

Changes