Authorization: Bearer header — no session cookie or CSRF token is needed.
List API Tokens
GET /api/api_tokens Return all API tokens that have been created for your organization. Secret values are never included in list or get responses — only the token ID, name, and creation timestamp.array
Array of token summary objects. The
token secret field is never returned here.Create an API Token
POST /api/api_tokens Create a new API token. The full secret value is returned only in this response — Springwinter does not store the plaintext token and cannot show it again.string
required
A descriptive label for the token. Choose a name that identifies its purpose or owner, for example
ci-deploy, terraform-prod, or monitoring-script.string
Unique token identifier. Store this alongside the secret for revocation purposes.
string
The label you provided.
string
The full bearer token secret. Begins with
swt_. This value is returned once only — copy it to a secrets manager immediately.string
ISO 8601 creation timestamp.
Revoke an API Token
DELETE /api/api_tokens/ Permanently revoke an API token. Any request using the revoked token will receive a401 Unauthorized response immediately after deletion.
string
required
The ID of the token to revoke. Retrieve the ID from the
GET /api/api_tokens response.Using Tokens in Requests
Pass the token in theAuthorization header on every API request:
Token security best practices
Token security best practices
- Use one token per system. Create a dedicated token for each CI/CD pipeline, script, or integration so you can revoke individual access without affecting others.
- Rotate tokens regularly. Create a replacement before revoking the old token to avoid downtime.
- Prefer least privilege. Tokens inherit full organization-level API access. Limit where tokens are stored and who can read them.
- Audit periodically. Review the token list in Settings → API Tokens and delete any tokens that are no longer in use.