public-api-tokens

Admin-only viewset for managing public-API tokens (SystemUser + ResourceAccess rows).

Supports create, list, retrieve, revoke, and editing resource grants.

POST /public-api-tokens/ creates a new SystemUser for the caller's organisation, persists the requested ResourceAccess rows, and returns the plaintext token once. The token is never recoverable after this response.

GET /public-api-tokens/ lists the caller's org tokens without secrets. GET /public-api-tokens/{id}/ retrieves a single token without secrets.

Every route here selects its organization with X-Organization-Id, on the terms the header is documented with everywhere else: optional for a caller with one active membership, required (400) for a caller with two or more, and 403 when it names an organization the caller is not an active member of.

get/public-api-tokens{format}

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Path parameters

format'.json' required

Query parameters

limitinteger

Number of results to return per page.

offsetinteger

The initial index from which to return the results.

Headers

X-Organization-Idstring

Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.

Response

countinteger required
nextstring uri nullable
previousstring uri nullable

Example response

{
  "count": 123,
  "next": "http://api.example.org/accounts/?offset=400&limit=100",
  "previous": "http://api.example.org/accounts/?offset=200&limit=100"
}

Changes