Use this API to interact with access tokens including:

List all group access tokens

GET /api/v4/groups/{id}/access_tokens

Lists all group access tokens for a specified group.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the group
revoked
Query
BooleanFilter tokens where revoked state matches parameter
Example: false
state
Query
StringFilter tokens which are either active or not
Allowed values: active, inactive
Example: active
created_before
Query
String (date-time)Filter tokens which were created before given datetime
Example: 2022-01-01T00:00:00Z
created_after
Query
String (date-time)Filter tokens which were created after given datetime
Example: 2021-01-01T00:00:00Z
last_used_before
Query
String (date-time)Filter tokens which were used before given datetime
Example: 2021-01-01T00:00:00Z
last_used_after
Query
String (date-time)Filter tokens which were used after given datetime
Example: 2022-01-01T00:00:00Z
expires_before
Query
String (date)Filter tokens which expire before given datetime
Example: 2022-01-01
expires_after
Query
String (date)Filter tokens which expire after given datetime
Example: 2021-01-01
search
Query
StringFilters tokens by name
Example: token
sort
Query
StringSort tokens
Example: created_at_desc

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessToken
400Bad Request—
404Not Found—

Create a group access token

POST /api/v4/groups/{id}/access_tokens

Creates a group access token for a specified group. You cannot create a token with an access level greater than your account. For example, a user with the Maintainer role cannot create a group access token with the Owner role. You must use a personal access token with this endpoint. You cannot authenticate with a group access token.

Parameters

NameTypeDescription
id
Path, required
StringThe group ID
Example: 2

Request body (application/json)

PropertyTypeDescription
access_levelIntegerThe access level of the token in the group
Allowed values: 10, 15, 20, 25, 30, 40, 50
Default: 40
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)The expiration date of the token. If ‘Require personal access token expiry’ is enabled, you must provide a valid value, if not, the token will never expire
Example: 2026-02-14
name
Required
StringThe name of the access token
Example: My token
scopes
Required
Array of stringsThe permissions of the token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
404Not Found—

Rotate a group access token

POST /api/v4/groups/{id}/access_tokens/self/rotate

Rotates a group access token by passing it to the API in a header.

Parameters

NameTypeDescription
id
Path, required
StringThe group ID

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—
405Method not allowed—

Retrieve details on a group access token

GET /api/v4/groups/{id}/access_tokens/{token_id}

Retrieves details on a specified group access token.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the group
token_id
Path, required
StringThe ID of the token

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessToken
400Bad Request—
404Not Found—

Revoke a group access token

DELETE /api/v4/groups/{id}/access_tokens/{token_id}

Revokes a specified group access token.

Parameters

NameTypeDescription
id
Path, required
StringThe group ID
token_id
Path, required
StringThe ID of the token

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not found—

Rotate a group access token

POST /api/v4/groups/{id}/access_tokens/{token_id}/rotate

Rotates a group access token. This immediately revokes the previous token and creates a token. Generally, this endpoint rotates a specific group access token by authenticating with a personal access token. You can also use a group access token to rotate itself. If you attempt to use this endpoint to rotate a token that was previously revoked, any active tokens from the same token family are revoked. This feature was introduced in GitLab 16.0.

Parameters

NameTypeDescription
id
Path, required
StringThe group ID
token_id
Path, required
StringThe ID of the token

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
404Not Found—

List all personal access tokens for a group service account

GET /api/v4/groups/{id}/service_accounts/{user_id}/personal_access_tokens

Lists all personal access tokens for a specified group service account

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
revoked
Query
BooleanFilter tokens where revoked state matches parameter
Example: false
state
Query
StringFilter tokens which are either active or not
Allowed values: active, inactive
Example: active
created_before
Query
String (date-time)Filter tokens which were created before given datetime
Example: 2022-01-01T00:00:00Z
created_after
Query
String (date-time)Filter tokens which were created after given datetime
Example: 2021-01-01T00:00:00Z
last_used_before
Query
String (date-time)Filter tokens which were used before given datetime
Example: 2021-01-01T00:00:00Z
last_used_after
Query
String (date-time)Filter tokens which were used after given datetime
Example: 2022-01-01T00:00:00Z
expires_before
Query
String (date)Filter tokens which expire before given datetime
Example: 2022-01-01
expires_after
Query
String (date)Filter tokens which expire after given datetime
Example: 2021-01-01
search
Query
StringFilters tokens by name
Example: token
sort
Query
StringSort tokens
Example: created_at_desc
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
user_id
Path, required
IntegerThe ID of the service account

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
400Bad Request—
401401 Unauthorized—
403Forbidden—
404404 Group Not Found—

Create a personal access token for a group service account

POST /api/v4/groups/{id}/service_accounts/{user_id}/personal_access_tokens

Creates a personal access token for a specified group service account. Available only for group Owners and administrators. This feature was introduced in GitLab 16.1.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
user_id
Path, required
IntegerThe ID of the service account

Request body (application/json)

PropertyTypeDescription
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)Expiration date of the access token in ISO format (YYYY-MM-DD). If undefined, the date is set to the maximum allowable lifetime limit
Example: 2021-01-31
name
Required
StringThe name of the access token
Example: My token
scopes
Required
Array of stringsThe array of scopes of the personal access token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

Revoke a personal access token for a group service account

DELETE /api/v4/groups/{id}/service_accounts/{user_id}/personal_access_tokens/{token_id}

Revokes a specified personal access token for a group service account.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
token_id
Path, required
IntegerThe ID of the personal access token
user_id
Path, required
IntegerThe ID of the service account

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Rotate a personal access token for a group service account

POST /api/v4/groups/{id}/service_accounts/{user_id}/personal_access_tokens/{token_id}/rotate

Rotates a specified personal access token for a group service account. This revokes the existing token and creates a token with the same name, description, and scopes.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
token_id
Path, required
IntegerThe ID of the personal access token
user_id
Path, required
IntegerThe ID of the service account

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

List all personal access tokens

GET /api/v4/personal_access_tokens

Lists all personal access tokens accessible by the authenticated user. For administrators, returns all personal access tokens in the instance. For non-administrators, returns all of their personal access tokens.

Parameters

NameTypeDescription
user_id
Query
IntegerFilter PATs by User ID
Example: 2
revoked
Query
BooleanFilter tokens where revoked state matches parameter
Example: false
state
Query
StringFilter tokens which are either active or not
Allowed values: active, inactive
Example: active
created_before
Query
String (date-time)Filter tokens which were created before given datetime
Example: 2022-01-01T00:00:00Z
created_after
Query
String (date-time)Filter tokens which were created after given datetime
Example: 2021-01-01T00:00:00Z
last_used_before
Query
String (date-time)Filter tokens which were used before given datetime
Example: 2021-01-01T00:00:00Z
last_used_after
Query
String (date-time)Filter tokens which were used after given datetime
Example: 2022-01-01T00:00:00Z
expires_before
Query
String (date)Filter tokens which expire before given datetime
Example: 2022-01-01
expires_after
Query
String (date)Filter tokens which expire after given datetime
Example: 2021-01-01
search
Query
StringFilters tokens by name
Example: token
sort
Query
StringSort tokens
Example: created_at_desc
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
400Bad Request—
401Unauthorized—

Retrieve a personal access token

GET /api/v4/personal_access_tokens/self

Retrieves a specified personal access token by passing it to the API in a header.

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
401Unauthorized—
404Not found—

Revoke a personal access token

DELETE /api/v4/personal_access_tokens/self

Revokes a personal access token by passing it to the API in a header.

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—

List all token associations

GET /api/v4/personal_access_tokens/self/associations

Lists all groups and projects accessible by the personal access token used to authenticate the request. Generally, this includes any groups or projects that the user is a member of.

Parameters

NameTypeDescription
min_access_level
Query
IntegerLimit by minimum access level of authenticated user
Allowed values: 10, 15, 20, 25, 30, 40, 50
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
400Bad Request—
401Unauthorized—
404Not found—

Rotate a personal access token

POST /api/v4/personal_access_tokens/self/rotate

Rotates a personal access token by passing it to the API in a header

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
401Unauthorized—
403Forbidden—
405Method not allowed—

Retrieve a personal access token

GET /api/v4/personal_access_tokens/{id}

Retrieves details for a specified personal access token. Administrators can retrieve details on any token. Non-administrators can only retrieve details on their own tokens.

Parameters

NameTypeDescription
id
Path, required
IntegerThe ID of a personal access token

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
400Bad Request—
401Unauthorized—
404Not found—

Revoke a personal access token

DELETE /api/v4/personal_access_tokens/{id}

Revokes a specified personal access token. Administrators can revoke tokens for any user. Non-administrators can only revoke their own tokens.

Parameters

NameTypeDescription
id
Path, required
IntegerThe ID of a personal access token

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

Rotate a personal access token

POST /api/v4/personal_access_tokens/{id}/rotate

Rotates a specified personal access token. This revokes the previous token and creates a token that expires after one week. Administrators can revoke tokens for any user. Non-administrators can only revoke their own tokens.

Parameters

NameTypeDescription
id
Path, required
IntegerThe ID of a personal access token

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

List all project access tokens

GET /api/v4/projects/{id}/access_tokens

Lists all project access tokens for a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the project
revoked
Query
BooleanFilter tokens where revoked state matches parameter
Example: false
state
Query
StringFilter tokens which are either active or not
Allowed values: active, inactive
Example: active
created_before
Query
String (date-time)Filter tokens which were created before given datetime
Example: 2022-01-01T00:00:00Z
created_after
Query
String (date-time)Filter tokens which were created after given datetime
Example: 2021-01-01T00:00:00Z
last_used_before
Query
String (date-time)Filter tokens which were used before given datetime
Example: 2021-01-01T00:00:00Z
last_used_after
Query
String (date-time)Filter tokens which were used after given datetime
Example: 2022-01-01T00:00:00Z
expires_before
Query
String (date)Filter tokens which expire before given datetime
Example: 2022-01-01
expires_after
Query
String (date)Filter tokens which expire after given datetime
Example: 2021-01-01
search
Query
StringFilters tokens by name
Example: token
sort
Query
StringSort tokens
Example: created_at_desc

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessToken
400Bad Request—
404Not Found—

Create a project access token

POST /api/v4/projects/{id}/access_tokens

Creates a project access token for a specified project. You cannot create a token with an access level greater than your account. For example, a user with the Maintainer role cannot create a project access token with the Owner role. You must use a personal access token with this endpoint. You cannot authenticate with a project access token.

Parameters

NameTypeDescription
id
Path, required
StringThe project ID
Example: 2

Request body (application/json)

PropertyTypeDescription
access_levelIntegerThe access level of the token in the project
Allowed values: 10, 15, 20, 25, 30, 40, 50
Default: 40
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)The expiration date of the token. If ‘Require personal access token expiry’ is enabled, you must provide a valid value, if not, the token will never expire
Example: 2026-02-14
name
Required
StringThe name of the access token
Example: My token
scopes
Required
Array of stringsThe permissions of the token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
404Not Found—

Rotate a project access token

POST /api/v4/projects/{id}/access_tokens/self/rotate

Rotates a project access token by passing it to the API in a header.

Parameters

NameTypeDescription
id
Path, required
StringThe project ID

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—
405Method not allowed—

Retrieve details on a project access token

GET /api/v4/projects/{id}/access_tokens/{token_id}

Retrieves details on a specified project access token.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the project
token_id
Path, required
StringThe ID of the token

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessToken
400Bad Request—
404Not Found—

Revoke a project access token

DELETE /api/v4/projects/{id}/access_tokens/{token_id}

Revokes a specified project access token.

Parameters

NameTypeDescription
id
Path, required
StringThe project ID
token_id
Path, required
StringThe ID of the token

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not found—

Rotate a project access token

POST /api/v4/projects/{id}/access_tokens/{token_id}/rotate

Rotates a project access token. This immediately revokes the previous token and creates a token. Generally, this endpoint rotates a specific project access token by authenticating with a personal access token. You can also use a project access token to rotate itself. If you attempt to use this endpoint to rotate a token that was previously revoked, any active tokens from the same token family are revoked. This feature was introduced in GitLab 16.0.

Parameters

NameTypeDescription
id
Path, required
StringThe project ID
token_id
Path, required
StringThe ID of the token

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
200OKAPIEntitiesResourceAccessTokenWithToken
400Bad Request—
404Not Found—

List all personal access tokens for a project service account

GET /api/v4/projects/{id}/service_accounts/{user_id}/personal_access_tokens

Lists all personal access tokens for a specified project service account

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
revoked
Query
BooleanFilter tokens where revoked state matches parameter
Example: false
state
Query
StringFilter tokens which are either active or not
Allowed values: active, inactive
Example: active
created_before
Query
String (date-time)Filter tokens which were created before given datetime
Example: 2022-01-01T00:00:00Z
created_after
Query
String (date-time)Filter tokens which were created after given datetime
Example: 2021-01-01T00:00:00Z
last_used_before
Query
String (date-time)Filter tokens which were used before given datetime
Example: 2021-01-01T00:00:00Z
last_used_after
Query
String (date-time)Filter tokens which were used after given datetime
Example: 2022-01-01T00:00:00Z
expires_before
Query
String (date)Filter tokens which expire before given datetime
Example: 2022-01-01
expires_after
Query
String (date)Filter tokens which expire after given datetime
Example: 2021-01-01
search
Query
StringFilters tokens by name
Example: token
sort
Query
StringSort tokens
Example: created_at_desc
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
user_id
Path, required
IntegerThe ID of the service account

Responses

CodeDescriptionSchema
200OKAPIEntitiesPersonalAccessToken
400Bad Request—
401401 Unauthorized—
403Forbidden—
404404 Project Not Found—

Create a personal access token for a project service account

POST /api/v4/projects/{id}/service_accounts/{user_id}/personal_access_tokens

Creates a personal access token for a specified project service account. Available only for project Owners, Maintainers, and administrators.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
user_id
Path, required
IntegerThe ID of the service account

Request body (application/json)

PropertyTypeDescription
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)Expiration date of the access token in ISO format (YYYY-MM-DD). If undefined, the date is set to the maximum allowable lifetime limit
Example: 2021-01-31
name
Required
StringThe name of the access token
Example: My token
scopes
Required
Array of stringsThe array of scopes of the personal access token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

Revoke a personal access token for a project service account

DELETE /api/v4/projects/{id}/service_accounts/{user_id}/personal_access_tokens/{token_id}

Revokes a specified personal access token for a project service account.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
token_id
Path, required
IntegerThe ID of the personal access token
user_id
Path, required
IntegerThe ID of the service account

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Rotate a personal access token for a project service account

POST /api/v4/projects/{id}/service_accounts/{user_id}/personal_access_tokens/{token_id}/rotate

Rotates a specified personal access token for a project service account. This revokes the existing token and creates a token with the same name, description, and scopes.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
token_id
Path, required
IntegerThe ID of the personal access token
user_id
Path, required
IntegerThe ID of the service account

Request body (application/json)

PropertyTypeDescription
expires_atString (date)The expiration date of the token
Example: 2021-01-31

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

Create a personal access token

POST /api/v4/user/personal_access_tokens

Creates a personal access token for the currently authenticated user. For security purposes, the token is limited to the k8s_proxy and self_rotate scope. Token values are included with the response, but cannot be retrieved later. This feature was introduced in GitLab 16.5.

Request body (application/json)

PropertyTypeDescription
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)Expiration date of the access token in ISO format (YYYY-MM-DD). If undefined, the date is set to the maximum allowable lifetime limit
Example: 2021-01-31
granular_scopesArray of objectsList of granular scopes to assign to the token
granular_scopes[].access
Required
StringAccess to configure for the granular scope
Allowed values: personal_projects, all_memberships, selected_memberships, user, instance
Minimum length: 1
granular_scopes[].group_idsArray of integersIDs of groups to associate with the granular scope, when access is selected_memberships
granular_scopes[].permissions
Required
Array of stringsList of permissions for the granular scope
granular_scopes[].project_idsArray of integersIDs of projects to associate with the granular scope, when access is selected_memberships
name
Required
StringThe name of the access token
Example: My token
scopesArray of stringsThe array of scopes of the personal access token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—

List all impersonation tokens for a user

GET /api/v4/users/{user_id}/impersonation_tokens

Lists all impersonation tokens for a specified user. Administrators only.

Parameters

NameTypeDescription
user_id
Path, required
IntegerThe ID of the user
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
state
Query
StringFilters (all|active|inactive) impersonation_tokens
Allowed values: all, active, inactive
Default: all

Responses

CodeDescriptionSchema
200OKAPIEntitiesImpersonationToken
400Bad Request—
404Not Found—

Create an impersonation token

POST /api/v4/users/{user_id}/impersonation_tokens

Creates an impersonation token. These tokens are used to act on behalf of a user and can perform API calls as well as Git read and write actions. These tokens are not visible to the associated user on their profile settings page. Token values are included with the response, but cannot be retrieved later. Administrators only.

Parameters

NameTypeDescription
user_id
Path, required
IntegerThe ID of the user

Request body (application/json)

PropertyTypeDescription
descriptionStringThe description of the personal access token
expires_atString (date)The expiration date in the format YEAR-MONTH-DAY of the impersonation token
granular_scopesArray of objectsList of granular scopes to assign to the token. Mutually exclusive with scopes
granular_scopes[].access
Required
StringAccess to configure for the granular scope
Allowed values: personal_projects, all_memberships, selected_memberships, user, instance
Minimum length: 1
granular_scopes[].group_idsArray of integersIDs of groups to associate with the granular scope, when access is selected_memberships
granular_scopes[].permissions
Required
Array of stringsList of permissions for the granular scope
granular_scopes[].project_idsArray of integersIDs of projects to associate with the granular scope, when access is selected_memberships
name
Required
StringThe name of the impersonation token
scopesArray of stringsThe array of scopes of the impersonation token. Mutually exclusive with granular_scopes

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesImpersonationTokenWithToken
400Bad Request—
404Not Found—

Retrieve an impersonation token for a user

GET /api/v4/users/{user_id}/impersonation_tokens/{impersonation_token_id}

Retrieves an impersonation token for a specified user. Administrators only.

Parameters

NameTypeDescription
user_id
Path, required
IntegerThe ID of the user
impersonation_token_id
Path, required
IntegerThe ID of the impersonation token

Responses

CodeDescriptionSchema
200OKAPIEntitiesImpersonationToken
400Bad Request—
404Not Found—

Revoke an impersonation token

DELETE /api/v4/users/{user_id}/impersonation_tokens/{impersonation_token_id}

Revokes an impersonation token for a specified user. Administrators only.

Parameters

NameTypeDescription
user_id
Path, required
IntegerThe ID of the user
impersonation_token_id
Path, required
IntegerThe ID of the impersonation token

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

Create a personal access token for a user

POST /api/v4/users/{user_id}/personal_access_tokens

Creates a personal access token for a user. Token values are included with the response, but cannot be retrieved later. Administrators only.

Parameters

NameTypeDescription
user_id
Path, required
IntegerThe ID of the user

Request body (application/json)

PropertyTypeDescription
descriptionStringThe description of the access token
Example: A token used for k8s
expires_atString (date)Expiration date of the access token in ISO format (YYYY-MM-DD). If undefined, the date is set to the maximum allowable lifetime limit
Example: 2021-01-31
name
Required
StringThe name of the access token
Example: My token
scopes
Required
Array of stringsThe array of scopes of the personal access token

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesPersonalAccessTokenWithToken
400Bad Request—
404Not Found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesImpersonationToken

PropertyTypeDescription
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
impersonationString—
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
revokedBoolean—
scopesArrayExample: ["api"]
user_idInteger (int64)Example: 3

APIEntitiesImpersonationTokenWithToken

PropertyTypeDescription
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
impersonationString—
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
revokedBoolean—
scopesArrayExample: ["api"]
tokenString—
user_idInteger (int64)Example: 3

APIEntitiesPersonalAccessToken

PropertyTypeDescription
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
revokedBoolean—
scopesArrayExample: ["api"]
user_idInteger (int64)Example: 3

APIEntitiesPersonalAccessTokenGranularScope

PropertyTypeDescription
accessStringExample: personal_projects
group_idInteger (int64)Example: 5
permissionsArrayExample: ["read_job"]
project_idInteger (int64)Example: 3

APIEntitiesPersonalAccessTokenWithToken

PropertyTypeDescription
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
revokedBoolean—
scopesArrayExample: ["api"]
tokenString—
user_idInteger (int64)Example: 3

APIEntitiesResourceAccessToken

PropertyTypeDescription
access_levelIntegerAllowed values: 10, 20, 30, 40, 50
Example: 40
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
resource_idIntegerExample: 1234
resource_typeStringAllowed values: project, group
Example: project
revokedBoolean—
scopesArrayExample: ["api"]
user_idInteger (int64)Example: 3

APIEntitiesResourceAccessTokenWithToken

PropertyTypeDescription
access_levelIntegerAllowed values: 10, 20, 30, 40, 50
Example: 40
activeBoolean—
created_atString (date-time)—
descriptionStringExample: Token to manage api
expires_atString (date-time)Example: 2020-08-31T15:53:00.073Z
granularBoolean—
granular_scopesArray of APIEntitiesPersonalAccessTokenGranularScope—
idInteger (int64)Example: 2
last_used_atString (date-time)Example: 2020-08-31T15:53:00.073Z
last_used_ipsArray of stringsThe five most recent unique IP addresses that have authenticated with this token. When the limit is reached, the oldest IP address is removed. The list updates once per minute per token
Example: ["127.0.0.1","127.0.0.2","127.0.0.3"]
nameStringExample: John Doe
resource_idIntegerExample: 1234
resource_typeStringAllowed values: project, group
Example: project
revokedBoolean—
scopesArrayExample: ["api"]
tokenString—
user_idInteger (int64)Example: 3