Personal Access Tokens
A personal access token (PAT) is how a script, an orchestrator, or a CI pipeline authenticates to the API. The token acts as you: it carries your permissions, and anything it does is recorded against your account.
Create a token
- Open Account Settings → Security and find Personal Access Tokens.
- Click Create token, name it, and set an expiry. The expiry cannot exceed your organization's maximum token lifetime.
- Copy the secret. It is shown once and cannot be retrieved later.
Creating or regenerating a token requires that you signed in recently; the console will ask you to re-authenticate if not.
Use a token
Send the token as a bearer credential, and name the organization you are acting in:
bash
curl https://<api-host>/api/v1/... \
-H "Authorization: Bearer <token>" \
-H "LakeSail-Organization-Id: <organization-id>"Some operations are refused to tokens and require an interactive sign-in, such as adding an email address or changing your password. The API reference marks them.
Rotate, expire, and delete
- Regenerate replaces the secret and sets a new expiry. The old secret stops working immediately.
- Expired tokens stop working but stay in your list until you delete them.
- Delete stops the token immediately. Organization Owners can still see a deleted token for a retention period afterwards.
Organization controls
Owners manage tokens for the whole organization:
- Settings → Access sets whether members may create tokens at all, and the maximum lifetime for new tokens (1 to 366 days; the default is 90). Disabling tokens stops every existing token immediately. Lowering the lifetime affects new tokens only.
- Settings → Secrets lists each member's active tokens, nearest expiry, and last use. From there an Owner can revoke any member's token. The owner sees that it was revoked, and by whom.
- Resetting a member's password revokes all of their tokens.
API reference
- Personal Access Tokens: create, list, regenerate, delete; organization-wide listing and revocation.
- Authentication: the sign-in endpoint for interactive sessions.
- Job Runs: create, hold and release, cancel, and retry runs; the operations an orchestrator uses.