Skip to content
NEXCANVAS

Account and running it · Chapter 29

API tokens

An API token is a key for a program. With it the program reads which boards there are and what has changed lately. It cannot change anything.

Switch it on first

The operator switches on Accounts may make API tokens under Settings, Server, API. Until then, nobody sees the option to create one.

Creating a token

  1. My account, Connections, New token.
  2. Give it a name, say “Dashboard”.
  3. Choose what it may read: all the spaces you may read, later ones too, or only certain ones.
  4. Under Runs out choose 30 days, 90 days, a year or never.
  5. Copy the token. It starts with nxa_ and appears only this one time.
My account
My account, Connections with the API tokens card, a token called Dashboard in it and the button for a new one
The tokens of an account.

In the list you see every token with its name and end date. A week before it runs out, nexcanvas marks it. An account can have up to 20 tokens.

Using it

The program sends the token in the header Authorization: Bearer nxa_… to the addresses under /api/v1. Which ones there are and what they return is described under For programs.

Cora saysA token never reads more than your account. Even an operator's token only sees the spaces the operator is a member of. And because nexcanvas only stores a checksum, nobody can show a lost token again; just make a new one.