Admin-only viewset for managing public-API tokens (SystemUser + ResourceAccess rows).
Supports create, list, retrieve, revoke, and editing resource grants.
POST /public-api-tokens/ creates a new SystemUser for the caller's organisation, persists the requested ResourceAccess rows, and returns the plaintext token once. The token is never recoverable after this response.
GET /public-api-tokens/ lists the caller's org tokens without secrets. GET /public-api-tokens/{id}/ retrieves a single token without secrets.
Every route here selects its organization with X-Organization-Id, on the terms the header is documented with everywhere else: optional for a caller with one active membership, required (400) for a caller with two or more, and 403 when it names an organization the caller is not an active member of.
Request
- The document declares no server URL.
- Auth: one of:
- HTTP bearer
- API key in cookie sessionid
Path parameters
Query parameters
Number of results to return per page.
The initial index from which to return the results.
Headers
Selects the active organization for this request. Optional for callers that belong to exactly one active organization — the single membership is resolved implicitly. Required when the caller has two or more active memberships; omitting it in that case returns 400. If the header names an organization the caller is not an active member of, the server returns 403.
Response
Example response
{
"count": 123,
"next": "http://api.example.org/accounts/?offset=400&limit=100",
"previous": "http://api.example.org/accounts/?offset=200&limit=100"
}Changes
- ○
added the new optional
headerrequest parameterX-Organization-Id
- ○
- ○
added the required property
//to the response with the status
- ○