Auth tokens let admin users access protected endpoints without a login session - used by external integrations, monitoring scripts or CI jobs that call the admin REST/API.
Creating a token
- Go to Admin → Auth tokens Click Add, select the user the token acts as
- Save - the generated token string is shown once; copy it immediately
Using a token
Send it with requests, e.g. as Authorization: Bearer <token> (or per integration instructions). Requests run with the permissions of the linked admin user.
Security
- Treat tokens like passwords - revoke any token you can't account for
- Delete tokens that are no longer used from the list
- All token usage appears in logs like normal admin activity