Account and running it · Chapter 29
API tokens
An API token is a key for a program. With it the program reads which boards there are and what has changed lately. It cannot change anything.
Switch it on first
The operator switches on Accounts may make API tokens under Settings, Server, API. Until then, nobody sees the option to create one.
Creating a token
- My account, Connections, New token.
- Give it a name, say “Dashboard”.
- Choose what it may read: all the spaces you may read, later ones too, or only certain ones.
- Under Runs out choose 30 days, 90 days, a year or never.
- Copy the token. It starts with
nxa_and appears only this one time.
In the list you see every token with its name and end date. A week before it runs out, nexcanvas marks it. An account can have up to 20 tokens.
Using it
The program sends the token in the header Authorization: Bearer nxa_… to the addresses under /api/v1. Which ones there are and what they return is described under For programs.
Cora saysA token never reads more than your account. Even an operator's token only sees the spaces the operator is a member of. And because nexcanvas only stores a checksum, nobody can show a lost token again; just make a new one.