Admin-only viewset for managing public-API tokens (SystemUser + ResourceAccess rows).
Supports create, list, retrieve, revoke, and editing resource grants.
POST /public-api-tokens/ creates a new SystemUser for the caller's organisation, persists the requested ResourceAccess rows, and returns the plaintext token once. The token is never recoverable after this response.
GET /public-api-tokens/ lists the caller's org tokens without secrets. GET /public-api-tokens/{id}/ retrieves a single token without secrets.
Every route here selects its organization with X-Organization-Id, on the terms the header is documented with everywhere else: optional for a caller with one active membership, required (400) for a caller with two or more, and 403 when it names an organization the caller is not an active member of.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Path parameters
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Response
Changes
- ○
added the new optional
headerrequest parameterX-Organization-Id
- ○
- ○
added the required property
to the response with the status
- ○