Skip to main content
API tokens let you authenticate programmatic requests to the Springwinter API without using a browser session or CSRF cookie. Use them in CI/CD pipelines, deployment scripts, infrastructure automation, or any environment where interactive sign-in is not practical.

Creating a Token

1

Open Settings → API Tokens

Click your organization name in the top navigation, select Settings, then choose API Tokens.
2

Click New Token

Click the New token button and enter a descriptive name that identifies where the token will be used — for example, github-actions-prod or deploy-script-staging.
3

Copy the token immediately

After you click Create, Springwinter displays the full token value exactly once. Copy it to a secure secret store right away — you cannot retrieve the value again after closing the dialog.Your token looks like this:
Store your token securely. It grants full organization access to the Springwinter API. If a token is compromised, revoke it immediately using the instructions below — all in-flight requests using that token will be rejected as soon as it is deleted.

Using a Token

Pass the token in the Authorization header of every API request:
Bearer token requests skip the cookie session and CSRF check entirely, so you do not need to fetch a CSRF token first. Here is a more complete example that creates a new project:
For use in GitHub Actions, store the token as a repository secret and reference it in your workflow:

Creating a Token via the API

You can also create tokens programmatically by sending a POST request with a name field:
The response includes the token secret, which is shown only in this response and never again:

Listing Your Tokens

Send a GET request to retrieve all tokens for your organization. The response returns token IDs and names — never the secret values.

Response fields

string
The unique identifier for the token. Use this ID to revoke the token.
string
The descriptive name you gave the token when you created it.
string
ISO 8601 timestamp of when the token was created.

Revoking a Token

Send a DELETE request with the token’s ID. The token is invalidated immediately — any subsequent requests using that token receive a 401 Unauthorized response.
Use a separate token for each environment and integration — for example, one for staging, one for production CI, and one for local scripts. That way, if one token is exposed, you can revoke it without disrupting the others.

Token API Reference