Developers
Service account tokens
A service account token is a long-lived bearer credential scoped to your tenant, created and managed from POST /v1/service-account-tokens. Unlike a user session, it never expires implicitly — you set an explicit expiry (or leave it open-ended) and revoke it the moment it's no longer needed.
How it works
- POST /v1/service-account-tokens with a name and the scopes you need
- Rotate to replace a token's value in place, or revoke it to stop it working immediately
- GET /v1/service-account-tokens/activity shows every privileged call made with your tokens
Good to know
- The plaintext token value is shown exactly once, at creation or rotation — it's stored hashed (SHA-256), never in plaintext
- A tenant can have at most 20 active tokens at a time; revoke unused ones to make room
- An unknown, expired, revoked, or wrong-scope token is rejected with the same generic 401 — the API never reveals which reason applied

