curl --request POST \
--url https://api.opal.dev/v1/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"token_label": "My API Token",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"expires_at": "2023-01-23T04:56:07.000Z"
}
'import requests
url = "https://api.opal.dev/v1/tokens"
payload = {
"token_label": "My API Token",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"expires_at": "2023-01-23T04:56:07.000Z"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
token_label: 'My API Token',
user_id: 'd4a7d928-783e-4599-8ec6-088d635a5bcc',
expires_at: '2023-01-23T04:56:07.000Z'
})
};
fetch('https://api.opal.dev/v1/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opal.dev/v1/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'token_label' => 'My API Token',
'user_id' => 'd4a7d928-783e-4599-8ec6-088d635a5bcc',
'expires_at' => '2023-01-23T04:56:07.000Z'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.opal.dev/v1/tokens"
payload := strings.NewReader("{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.opal.dev/v1/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.opal.dev/v1/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}"
response = http.request(request)
puts response.read_body{
"token": {
"token_id": "f454d283-ca87-4a8a-bdbb-df212eca5353",
"created_at": "2022-01-23T04:56:07.000Z",
"token_preview": "ab123",
"token_label": "My API Token",
"creator_user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"access_level": "READ_ONLY"
},
"signed_token": "opal_pat_abc123..."
}Create token
Creates a first-party API token. Omit user_id (or set it to the
caller’s ID) to create a token for yourself. Set user_id to a service
user’s ID to mint a token that authenticates as that service user.
Creating a token for another human user is not allowed.
The signed_token value in the response is the secret credential and is
only returned once at creation time.
curl --request POST \
--url https://api.opal.dev/v1/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"token_label": "My API Token",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"expires_at": "2023-01-23T04:56:07.000Z"
}
'import requests
url = "https://api.opal.dev/v1/tokens"
payload = {
"token_label": "My API Token",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"expires_at": "2023-01-23T04:56:07.000Z"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
token_label: 'My API Token',
user_id: 'd4a7d928-783e-4599-8ec6-088d635a5bcc',
expires_at: '2023-01-23T04:56:07.000Z'
})
};
fetch('https://api.opal.dev/v1/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opal.dev/v1/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'token_label' => 'My API Token',
'user_id' => 'd4a7d928-783e-4599-8ec6-088d635a5bcc',
'expires_at' => '2023-01-23T04:56:07.000Z'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.opal.dev/v1/tokens"
payload := strings.NewReader("{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.opal.dev/v1/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.opal.dev/v1/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"token_label\": \"My API Token\",\n \"user_id\": \"d4a7d928-783e-4599-8ec6-088d635a5bcc\",\n \"expires_at\": \"2023-01-23T04:56:07.000Z\"\n}"
response = http.request(request)
puts response.read_body{
"token": {
"token_id": "f454d283-ca87-4a8a-bdbb-df212eca5353",
"created_at": "2022-01-23T04:56:07.000Z",
"token_preview": "ab123",
"token_label": "My API Token",
"creator_user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"access_level": "READ_ONLY"
},
"signed_token": "opal_pat_abc123..."
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Information needed to create a first-party API token.
A human-readable label for the token.
"My API Token"
The access level of an API token.
READ_ONLY, FULL_ACCESS The ID of the user the token should authenticate as. Omit or set to the caller's ID to create a personal token. Set to a service user's ID to mint a token for that service user.
"d4a7d928-783e-4599-8ec6-088d635a5bcc"
Optional expiration time for the token.
"2023-01-23T04:56:07.000Z"
Response
The created API token. signed_token is only returned on creation.
The created API token. signed_token is the secret credential and is
only returned once at creation time.
A first-party API token.
Show child attributes
Show child attributes
{
"token_id": "f454d283-ca87-4a8a-bdbb-df212eca5353",
"created_at": "2022-01-23T04:56:07.000Z",
"token_preview": "ab123",
"token_label": "My API Token",
"creator_user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"user_id": "d4a7d928-783e-4599-8ec6-088d635a5bcc",
"access_level": "READ_ONLY"
}
The secret token string. Store this securely; it is only returned once at creation time.
"opal_pat_abc123..."
Was this page helpful?