Skip to main content

Token administration

This page is for Super Admins issuing credentials to a developer, rather than for the developer consuming them.


Who can issue a token​

API tokens are issued by an AnchorPoint Super Admin from the admin application, or by an operator running api:token generate on the server. No other role can create, rotate, or revoke them.

What to ask the developer for​

Before creating a token, collect:

DetailWhy it matters
NameIdentifies the integration in the token list, e.g. marketing-site-production. Use one token per application and per environment so you can revoke one without breaking the others.
ExpiryWhether the token should expire, and when. A token with an expires_at in the past returns 401 on every request from that moment.

Handing the token over​

The token is a 64-character random string.

The secret is shown only once

It is displayed at the moment it is created or rotated. Only a SHA-256 hash is stored, so it cannot be looked up again afterwards — not by you, and not by AnchorPoint support. If it is lost, the only remedy is a rotation.

Send it over a channel the developer already trusts for secrets (a password manager or secret store), not in an email or chat message that will sit in a mailbox.

Rotating, revoking, and deleting​

ActionEffect
RotateIssues a new secret under the same token. The old secret stops working the moment the new one is issued, so coordinate the swap with the developer.
RevokeThe token returns 401 on every request, immediately.
DeleteThe token returns 401, and its name cannot be reused.
ExpireSame as revoking, but happens automatically when expires_at passes.

Because a rotation invalidates the old secret instantly, ask the developer whether their application reads the token at request time or only at boot. If it reads at boot, the swap needs a redeploy — see Handling a rotated token without downtime.

Spotting dormant integrations​

Every successful request stamps a last_used_at timestamp on the token, throttled to one write per minute. A token with an old or empty last_used_at is a candidate for deletion — confirm with the owner first, since some integrations run only seasonally.

What a token can and cannot reach​

A token is not scoped to a user. Anyone holding it can read the public course and class catalogue — the same data a visitor to your public registration page could see. It cannot read student records, registrations, or payments, and it cannot write anything.