Skip to content

API tokens

Everything the web UI does goes through the public REST API, at https://<your Controller>:8080/api/v1.

On your Account page, under API tokens, choose Create token. Give it a name, an expiry, and optionally limit it to some of your permissions. The token is shown once.

A limited token can do only what both it and you may do. Tokens cannot create other tokens or change your password.

Send it as a bearer token:

Terminal window
curl -H "Authorization: Bearer skp_…" https://shardkeep.example.com:8080/api/v1/servers

With the Controller’s self-signed certificate, tell your tool to trust it (for example curl --cacert), or configure your own certificate.

Revoke a token from the same page when you no longer need it. Disabling your account revokes all of them.