Skip to main content
POST
cURL

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
expiration_seconds
string

Token expiration in seconds. Minimum is 300 seconds (5 minutes), maximum is 86400*365 seconds (1 year). To create a non-expiring token, set the value to 0.

resource_scope_keys
string[]

This property restricts the created token's access only to resources that sit within the hierarchy/hierarchies defined by resource_scope_keys. Important: this does not give access to the resources by itself; it is a filter that is applied on top of the existing access rights of the account for which the token is being created.

role_scopes
string[]

This property restricts the created token to the permissions granted by the given roles, identified by their role ID (e.g. viewer or spiideo_viewer). The roles are treated purely as sets of permissions: the account does not need to hold these roles itself, and the token can never do more than the account can. Important: like resource_scope_keys, this is a filter on top of the account's existing access; it does not grant access by itself. At most 5 roles can be given.

permission_scopes
string[]

This property restricts the created token to the given permissions (e.g. event.event.get). A scoped wildcard such as event.* is allowed. When combined with role_scopes, the token is restricted to the intersection of both; the most restrictive interpretation always wins. Important: like resource_scope_keys, this is a filter on top of the account's existing access; it does not grant access by itself. At most 10 permissions can be given.

Response

OK

token
string

Created token