post_api_management_v1_api_tokens
const url = 'https://example.com/api/management/v1/api-tokens';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"expires_at":"2026-04-15T12:00:00Z","label":"example","scopes":["example"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/management/v1/api-tokens \ --header 'Content-Type: application/json' \ --data '{ "expires_at": "2026-04-15T12:00:00Z", "label": "example", "scopes": [ "example" ] }'Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
Examplegenerated
{ "expires_at": "2026-04-15T12:00:00Z", "label": "example", "scopes": [ "example" ]}Responses
Section titled “ Responses ”An instance-level token limited to the runner scopes, shown once
object
#987 Stage A — set when the token is bound to an ORGANIZATION instead of a single workspace. Both null is the global/bootstrap shape.
Examplegenerated
{ "created_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "fingerprint": "example", "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "label": "example", "last_used_at": "2026-04-15T12:00:00Z", "organization_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "revoked_at": "2026-04-15T12:00:00Z", "scopes": [ "example" ], "token": "example", "workspace_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"}Only an instance-level token with tokens:write may mint one
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}A scope outside management:runners:{read,write,*}
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}