Skip to main content
POST
Create a personal access token

Authorizations

Authorization
string
header
required

Personal access token (izap_pat_…) sent as Authorization: Bearer ; dashboard session JWTs are also accepted.

Body

application/json

Mint a new token. expires_in_days omitted/null means it never expires.

name
string
required

Human-readable label for the token.

Required string length: 1 - 200
expires_in_days
integer | null

Days until the token expires. Null for a non-expiring token.

Required range: 0 < x <= 3650
scopes
string[] | null

Optional permission scopes (Permission enum values). Omitted or empty means full access within the credential's normal permissions.

Response

Successful Response

Returned once at creation — the only time the plaintext token is exposed.

created
string<date-time>
required
expires_at
string<date-time> | null
required
id
string<uuid>
required
last_used_at
string<date-time> | null
required
name
string
required
revoked
boolean
required
token
string
required

The plaintext token. Store it now; it cannot be retrieved again.

token_prefix
string
required

Non-secret leading chars, e.g. 'izap_pat_AbC'.

last_four
string | null

Last four chars of the token, for recognition.

scopes
string[] | null

Permission scopes. Null means full access within the credential's normal permissions.