Auth tokens let admin users access protected endpoints without a login session - used by external integrations, monitoring scripts or CI jobs that call the admin REST/API.


Creating a token

  1. Go to Admin → Auth tokens Click Add, select the user the token acts as
  2. Save - the generated token string is shown once; copy it immediately

Using a token

Send it with requests, e.g. as Authorization: Bearer <token> (or per integration instructions). Requests run with the permissions of the linked admin user.


Security

  • Treat tokens like passwords - revoke any token you can't account for
  • Delete tokens that are no longer used from the list
  • All token usage appears in logs like normal admin activity