Skip to navigation

Request a new token

Request a new token granting access to the MK.IO API. There are four types of tokens.

  • ‘restricted’ tokens can have an expireDate set to up to a year in the future grant a reduced set of capabilities. Please see our online documentation for a description of how the capabilities are defined.
  • ‘login’ tokens are short-lived and grant the full user capabilities.
  • ‘full-access’ tokens can have an expireDate set to up to a year in the future and grant the full user capabilities.
  • ‘ephemeral’ tokens are short-lived and grant a reduced set of capabilities, similar to ‘restricted’ tokens.

Where possible you should prefer ‘restricted’ tokens over ‘full-access’ tokens to reduce the impact if one is exposed accidentally.

An API token allows access to MK.IO to anyone who has a copy of it - you should treat these like your car keys and keep them safe.

Requires authentication; no additional RBAC permissions required.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Request

This endpoint expects an object.
organizationIdstringRequiredformat: "uuid"
ID of the organization that this token allows access to.
typeenumRequired
Type of token.
Allowed values:
descriptionstringOptional0-128 characters
Description of the token. Max 128 characters.
expireDatedatetimeOptional
Token expiration date. Maximum one year after creation.
permissionsmap from strings to anyOptional

Token permissions. Only needed if the type is one of '('restricted', 'ephemeral')'.

Response

Created
metadataobject
Token metadata.
specobject
Token spec.
kindstringOptional
The kind of record.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error
500
Internal Server Error