- A bearer token, starting with
nsrt_, that authenticates requests. Namespace returns it only once, when the token is created. - A token ID, starting with
tok_, that identifies the token when you list or revoke it. It is not a secret.
tenantClient, created from a tenant token.
Create a revokable token
The request needs a name that is unique within the tenant, an expiry of up to one year, and at least one grant listing what the token can do. This token can create and manage instances, which is all a CI pipeline needs:Use a revokable token
A revokable token works like any other bearer token. Pass it to a client, and every request acts inside the tenant with the token’s grants:In practice, the system that received the token, such as a CI pipeline, usually reads it from a secret or environment variable rather than keeping it in a variable.
List revokable tokens
Listing returns each token’s ID, name, expiry, grants, and state, but never the bearer token. By default, only active tokens are returned. SetincludeRevoked to see revoked tokens as well.
Output
paginationCursor into the next request until a page comes back empty.
Revoke a revokable token
Revoke a token by its ID. The next request made with its bearer token fails as unauthenticated.includeRevoked, with revokedAt recording when it was revoked and revokedByActorId identifying who revoked it.
Tokens tied to a member
Every token above is tenant-scoped, which is the default. A token can instead be tied to the member who creates it by settingscope to TENANT_MEMBERSHIP_SCOPE. Such a token stops working when that member leaves the tenant, and it is the only kind that can be created without an expiry.
This token has no expiresAt, so it stays valid until it is revoked or its creator leaves the tenant:
expiresAt on a member-scoped token, with the same one-year limit as tenant-scoped tokens.
Next steps
Tenant tokens
Short-lived tokens for your own service.
Multi-tenancy
How tenants isolate your customers.