POST /api/tokens
Mint an API token. The secret is returned once and never again — only its hash is stored
Requires the admin permission (or admin).
Request
{
"label": "ci",
"perms": [
"deploy",
"read"
]
}
Response
{
"id": "01a0…",
"token": "genroc_sk_…",
"label": "ci",
"perms": [
"deploy",
"read"
]
}
Fails with 400, 500.
GET /api/tokens
List API tokens. Secrets are never included — the row cannot produce one
Requires the admin permission (or admin).
Response
{
"items": []
}
Fails with 400, 500.
DELETE /api/tokens/{id}
Revoke an API token. Takes effect on the next request that presents it
Requires the admin permission (or admin).
| Parameter | In | Description |
|---|---|---|
id | path | The token id, as GET /tokens lists it |
Response
{
"revoked": true
}
Fails with 400, 404, 500.