Where to find it
In the admin, click the Settings gear in the top bar. In the Settings sidebar, under System, select API Tokens. If you don’t see API Tokens, your role doesn’t have access to Developer. To open the screen, your role needs at least View only for Developer, in the Settings card on the role’s Permissions tab. See Roles. If your role has View only for Developer, the Generate Token and Create Public Token buttons and each token’s actions menu are hidden. Full access shows them. To choose a role when you create an API token, your role also needs at least View only for Roles, in the same Settings card. To create a role from the panel, it needs Full access for Roles.What’s on the screen
The screen has two cards: API Tokens and Public Tokens. Each card lists your company’s tokens of that kind and has a search box that finds tokens by label or name.API Tokens card
The card reminds you that a token is shown only once, when you create it. Click Generate Token to create one. The list has these columns:- Token Label: the name you gave the token. You can rename it from the list. See Edit an API token.
- Role: the role that determines the token’s permissions. You can change it from the list.
- API Token: a masked version of the token, with a lock icon. The full token isn’t shown here.
- Created: the date the token was created.
- Expires: the date the token expires, or Never expires. Once the date has passed, it shows in red with (Expired).
Public Tokens card
Public tokens are client-side tokens for front-end integrations, such as the DAM Picker SDK. Each one has the scopes and optional domain allowlist you choose when you create it. Click Create Public Token to create one. The list has these columns:- Name: the name you gave the token.
- Token: a masked version of the token, with a lock icon.
- Scopes: what the token can access, such as
dam:browse. - Domain Allowlist: the domains you added to the token, or All domains if you didn’t add any.
- Expires: the date the token expires, or Never expires. Once the date has passed, it shows in red with (Expired).
- Created: the date the token was created.
The Create API Token panel
The panel opens on the right when you click Generate Token.- Token Label: a descriptive name to help you identify the token later. It’s required and must be unique.
- Role: the role determines what permissions the token has. It’s required. Search for or select one of your company’s roles, or choose + Create new role… to create one. After you select a role, click Role Permissions to see its permissions.
- Expiration Date: the date the token should expire. Leave it empty for a token that never expires.
The Create Public Token panel
The panel opens on the right when you click Create Public Token.- Name: a descriptive name to identify the token. It’s required and must be unique.
- Scopes: what the token can access. All scopes are selected when the panel opens. Clear the ones the token doesn’t need, or use Select All or Deselect All. Keep at least one selected.
- Domain Allowlist: optional. Type a domain, such as
shop.example.com, then click Add or press Enter. To remove a domain, click the × next to it. Leave the list empty to allow all domains. - Expiration: when the token expires, counted from when you create it: 1 hour, 24 hours, 7 days, 30 days or Never expires. 1 hour is selected when the panel opens. A token set to Never expires needs at least one domain in Domain Allowlist.
After you create a token
Once the token is created, the panel changes to Token Created for an API token, or Public Token Created for a public token. It shows the full token under Your API Token or Your Public Token. This is the only time you can see it.- Click Copy to copy the token. The button changes to Copied.
- For an API token, the How to use this token box shows the Base URL and Header your developer needs, with a View the API reference link.
- The Next Steps box suggests what to do with the token.
- Click Done to close the panel.
Create an API token
1
Open the panel
On the API Tokens card, click Generate Token. The Create API Token panel opens.
2
Name the token
In Token Label, enter a name that helps you identify the token later.
3
Choose a role
In Role, select the role whose permissions the token should have. To create a role for it, choose + Create new role…, enter the role’s name and permissions in the Create Role panel, and click Save. The new role is then selected.
4
Set an expiration date
To have the token expire, select a date in Expiration Date. Leave it empty for a token that never expires.
5
Create and copy the token
Click Create Token. In the Token Created panel, click Copy, then click Done. Store the token in a secure location, such as your application’s environment variables, and never commit it to version control.
Create a public token
1
Open the panel
On the Public Tokens card, click Create Public Token. The Create Public Token panel opens.
2
Name the token
In Name, enter a name that identifies the token.
3
Choose the scopes
Under Scopes, clear each scope the token doesn’t need. Keep at least one selected.
4
Add domains
Type each domain under Domain Allowlist and click Add. You can leave the list empty.
5
Choose an expiration
In Expiration, choose when the token expires. If you choose Never expires, add at least one domain in the previous step.
6
Create and copy the token
Click Create Token. In the Public Token Created panel, click Copy, then click Done.
Edit an API token
You can rename an API token from the list. Renaming a token or changing its role needs Full access for Developer.1
Start editing the label
In the Token Label column, click the token’s label or the pencil icon next to it.
2
Save the new label
Type the new label, then press Enter or click outside the field. If the label is empty or another API token already uses it, an error appears and the old label stays.
Delete a token
To revoke a token, delete it.1
Check the token isn't in use
Make sure no app or integration still uses the token.
2
Delete the token
On the API Tokens or Public Tokens card, open the token’s actions menu and choose Delete. Delete takes effect right away, without asking you to confirm. The token disappears from the list, and you can’t undo this.
Frequently asked questions
Can I see a token again after I close the panel?
Can I see a token again after I close the panel?
No. The full token appears only once, right after you create it. The lists show only a masked version. If you lose a token, create a new one and delete the old one.
What's the difference between API tokens and public tokens?
What's the difference between API tokens and public tokens?
An API token has the permissions of the role you choose. Store it in a secure location and never commit it to version control. A public token is designed for client-side use, such as front-end integrations. When you create one, choose only the scopes the integration needs. For how developers send a token with their requests, see Authentication.