Skip to content

Personal Access Tokens ​

A personal access token (PAT) is how a script, an orchestrator, or a CI pipeline authenticates to the API. The token acts as you: it carries your permissions, and anything it does is recorded against your account.

Create a token ​

  1. Open Account Settings → Security and find Personal Access Tokens.
  2. Click Create token, name it, and set an expiry. The expiry cannot exceed your organization's maximum token lifetime.
  3. Copy the secret. It is shown once and cannot be retrieved later.

Creating or regenerating a token requires that you signed in recently; the console will ask you to re-authenticate if not.

Use a token ​

Send the token as a bearer credential, and name the organization you are acting in:

bash
curl https://<api-host>/api/v1/... \
  -H "Authorization: Bearer <token>" \
  -H "LakeSail-Organization-Id: <organization-id>"

Some operations are refused to tokens and require an interactive sign-in, such as adding an email address or changing your password. The API reference marks them.

Rotate, expire, and delete ​

  • Regenerate replaces the secret and sets a new expiry. The old secret stops working immediately.
  • Expired tokens stop working but stay in your list until you delete them.
  • Delete stops the token immediately. Organization Owners can still see a deleted token for a retention period afterwards.

Organization controls ​

Owners manage tokens for the whole organization:

  • Settings → Access sets whether members may create tokens at all, and the maximum lifetime for new tokens (1 to 366 days; the default is 90). Disabling tokens stops every existing token immediately. Lowering the lifetime affects new tokens only.
  • Settings → Secrets lists each member's active tokens, nearest expiry, and last use. From there an Owner can revoke any member's token. The owner sees that it was revoked, and by whom.
  • Resetting a member's password revokes all of their tokens.

API reference ​

  • Personal Access Tokens: create, list, regenerate, delete; organization-wide listing and revocation.
  • Authentication: the sign-in endpoint for interactive sessions.
  • Job Runs: create, hold and release, cancel, and retry runs; the operations an orchestrator uses.

Can't find the answer here? Email us: support@lakesail.com