Skip to main content
Use the API Tokens screen to create and revoke the tokens that authenticate API and storefront requests for your company. For how developers send a token with their requests, see Authentication.

Where to find it

In the admin, click the Settings gear in the top bar. In the Settings sidebar, under System, select API Tokens. If you don’t see API Tokens, your role doesn’t have access to Developer. To open the screen, your role needs at least View only for Developer, in the Settings card on the role’s Permissions tab. See Roles. If your role has View only for Developer, the Generate Token and Create Public Token buttons and each token’s actions menu are hidden. Full access shows them. To choose a role when you create an API token, your role also needs at least View only for Roles, in the same Settings card. To create a role from the panel, it needs Full access for Roles.

What’s on the screen

The screen has two cards: API Tokens and Public Tokens. Each card lists your company’s tokens of that kind and has a search box that finds tokens by label or name.

API Tokens card

The card reminds you that a token is shown only once, when you create it. Click Generate Token to create one. The list has these columns:
  • Token Label: the name you gave the token. You can rename it from the list. See Edit an API token.
  • Role: the role that determines the token’s permissions. You can change it from the list.
  • API Token: a masked version of the token, with a lock icon. The full token isn’t shown here.
  • Created: the date the token was created.
  • Expires: the date the token expires, or Never expires. Once the date has passed, it shows in red with (Expired).
Each token’s actions menu has Delete.

Public Tokens card

Public tokens are client-side tokens for front-end integrations, such as the DAM Picker SDK. Each one has the scopes and optional domain allowlist you choose when you create it. Click Create Public Token to create one. The list has these columns:
  • Name: the name you gave the token.
  • Token: a masked version of the token, with a lock icon.
  • Scopes: what the token can access, such as dam:browse.
  • Domain Allowlist: the domains you added to the token, or All domains if you didn’t add any.
  • Expires: the date the token expires, or Never expires. Once the date has passed, it shows in red with (Expired).
  • Created: the date the token was created.
Each token’s actions menu has Delete. You can’t change a public token after you create it. To use different settings, create a new public token and delete the old one.

The Create API Token panel

The panel opens on the right when you click Generate Token.
  • Token Label: a descriptive name to help you identify the token later. It’s required and must be unique.
  • Role: the role determines what permissions the token has. It’s required. Search for or select one of your company’s roles, or choose + Create new role… to create one. After you select a role, click Role Permissions to see its permissions.
  • Expiration Date: the date the token should expire. Leave it empty for a token that never expires.
Create Token becomes available once you enter a label and select a role.

The Create Public Token panel

The panel opens on the right when you click Create Public Token.
  • Name: a descriptive name to identify the token. It’s required and must be unique.
  • Scopes: what the token can access. All scopes are selected when the panel opens. Clear the ones the token doesn’t need, or use Select All or Deselect All. Keep at least one selected.
  • Domain Allowlist: optional. Type a domain, such as shop.example.com, then click Add or press Enter. To remove a domain, click the × next to it. Leave the list empty to allow all domains.
  • Expiration: when the token expires, counted from when you create it: 1 hour, 24 hours, 7 days, 30 days or Never expires. 1 hour is selected when the panel opens. A token set to Never expires needs at least one domain in Domain Allowlist.
Create Token becomes available once you enter a name and select at least one scope. These are the scopes you can choose, and how the Scopes column shows each one:

After you create a token

Once the token is created, the panel changes to Token Created for an API token, or Public Token Created for a public token. It shows the full token under Your API Token or Your Public Token. This is the only time you can see it.
  • Click Copy to copy the token. The button changes to Copied.
  • For an API token, the How to use this token box shows the Base URL and Header your developer needs, with a View the API reference link.
  • The Next Steps box suggests what to do with the token.
  • Click Done to close the panel.
Copy the token before you close the panel. You can’t see it again.

Create an API token

1

Open the panel

On the API Tokens card, click Generate Token. The Create API Token panel opens.
2

Name the token

In Token Label, enter a name that helps you identify the token later.
3

Choose a role

In Role, select the role whose permissions the token should have. To create a role for it, choose + Create new role…, enter the role’s name and permissions in the Create Role panel, and click Save. The new role is then selected.
4

Set an expiration date

To have the token expire, select a date in Expiration Date. Leave it empty for a token that never expires.
5

Create and copy the token

Click Create Token. In the Token Created panel, click Copy, then click Done. Store the token in a secure location, such as your application’s environment variables, and never commit it to version control.

Create a public token

1

Open the panel

On the Public Tokens card, click Create Public Token. The Create Public Token panel opens.
2

Name the token

In Name, enter a name that identifies the token.
3

Choose the scopes

Under Scopes, clear each scope the token doesn’t need. Keep at least one selected.
4

Add domains

Type each domain under Domain Allowlist and click Add. You can leave the list empty.
5

Choose an expiration

In Expiration, choose when the token expires. If you choose Never expires, add at least one domain in the previous step.
6

Create and copy the token

Click Create Token. In the Public Token Created panel, click Copy, then click Done.

Edit an API token

You can rename an API token from the list. Renaming a token or changing its role needs Full access for Developer.
1

Start editing the label

In the Token Label column, click the token’s label or the pencil icon next to it.
2

Save the new label

Type the new label, then press Enter or click outside the field. If the label is empty or another API token already uses it, an error appears and the old label stays.
To change a token’s role, select a different role in its Role column. The change saves right away. You can’t change a token’s expiration date on this screen. To use a different one, create a new token and delete the old one.

Delete a token

To revoke a token, delete it.
1

Check the token isn't in use

Make sure no app or integration still uses the token.
2

Delete the token

On the API Tokens or Public Tokens card, open the token’s actions menu and choose Delete. Delete takes effect right away, without asking you to confirm. The token disappears from the list, and you can’t undo this.
To replace a token, for example one you lost, create a new token, switch your app to it, then delete the old one.

Frequently asked questions

No. The full token appears only once, right after you create it. The lists show only a masked version. If you lose a token, create a new one and delete the old one.
In the Create API Token panel, enter a Token Label and select a Role. In the Create Public Token panel, enter a Name and select at least one scope.If an error appears when you click it, check that no other token of the same kind already uses the label or name. For a public token set to Never expires, also check that you added at least one domain.
An API token has the permissions of the role you choose. Store it in a secure location and never commit it to version control. A public token is designed for client-side use, such as front-end integrations. When you create one, choose only the scopes the integration needs. For how developers send a token with their requests, see Authentication.