Token administration
This page is for Super Admins issuing credentials to a developer, rather than for the developer consuming them.
Who can issue a token
API tokens are issued by an AnchorPoint Super Admin from the admin application, or by an operator running api:token generate on the server. No other role can create, rotate, or revoke them.
What to ask the developer for
Before creating a token, collect:
| Detail | Why it matters |
|---|---|
| Name | Identifies the integration in the token list, e.g. marketing-site-production. Use one token per application and per environment so you can revoke one without breaking the others. |
| Expiry | Whether the token should expire, and when. A token with an expires_at in the past returns 401 on every request from that moment. |
Handing the token over
The token is a 64-character random string.
It is displayed at the moment it is created or rotated. Only a SHA-256 hash is stored, so it cannot be looked up again afterwards — not by you, and not by AnchorPoint support. If it is lost, the only remedy is a rotation.
Send it over a channel the developer already trusts for secrets (a password manager or secret store), not in an email or chat message that will sit in a mailbox.
Rotating, revoking, and deleting
| Action | Effect |
|---|---|
| Rotate | Issues a new secret under the same token. The old secret stops working the moment the new one is issued, so coordinate the swap with the developer. |
| Revoke | The token returns 401 on every request, immediately. |
| Delete | The token returns 401, and its name cannot be reused. |
| Expire | Same as revoking, but happens automatically when expires_at passes. |
Because a rotation invalidates the old secret instantly, ask the developer whether their application reads the token at request time or only at boot. If it reads at boot, the swap needs a redeploy — see Handling a rotated token without downtime.
Spotting dormant integrations
Every successful request stamps a last_used_at timestamp on the token, throttled to one write per minute. A token with an old or empty last_used_at is a candidate for deletion — confirm with the owner first, since some integrations run only seasonally.
What a token can and cannot reach
A token is not scoped to a user. Anyone holding it can read the public course and class catalogue — the same data a visitor to your public registration page could see. It cannot read student records, registrations, or payments, and it cannot write anything.