Skip to main content
API tokens are organization-scoped credentials for programmatic access to Springwinter. Every member of an organization shares access to the same token list, so tokens you create are visible to teammates and vice versa. You can manage tokens through the dashboard at Settings → API Tokens, or through the endpoints documented here. Authenticate requests by passing the token in an Authorization: Bearer header — no session cookie or CSRF token is needed.

List API Tokens

GET /api/api_tokens Return all API tokens that have been created for your organization. Secret values are never included in list or get responses — only the token ID, name, and creation timestamp.
array
Array of token summary objects. The token secret field is never returned here.

Create an API Token

POST /api/api_tokens Create a new API token. The full secret value is returned only in this response — Springwinter does not store the plaintext token and cannot show it again.
The token secret is returned only in the POST /api/api_tokens response. Springwinter cannot retrieve it again after this call. Store it securely in a secrets manager, CI/CD environment variable, or password vault immediately. If you lose the secret, delete the token and create a new one.
string
required
A descriptive label for the token. Choose a name that identifies its purpose or owner, for example ci-deploy, terraform-prod, or monitoring-script.
string
Unique token identifier. Store this alongside the secret for revocation purposes.
string
The label you provided.
string
The full bearer token secret. Begins with swt_. This value is returned once only — copy it to a secrets manager immediately.
string
ISO 8601 creation timestamp.

Revoke an API Token

DELETE /api/api_tokens/ Permanently revoke an API token. Any request using the revoked token will receive a 401 Unauthorized response immediately after deletion.
string
required
The ID of the token to revoke. Retrieve the ID from the GET /api/api_tokens response.

Using Tokens in Requests

Pass the token in the Authorization header on every API request:
In GitHub Actions, store the token as a repository secret (SPRINGWINTER_TOKEN) and reference it with ${{ secrets.SPRINGWINTER_TOKEN }}. Never hard-code the token in source files or commit it to version control.
  • Use one token per system. Create a dedicated token for each CI/CD pipeline, script, or integration so you can revoke individual access without affecting others.
  • Rotate tokens regularly. Create a replacement before revoking the old token to avoid downtime.
  • Prefer least privilege. Tokens inherit full organization-level API access. Limit where tokens are stored and who can read them.
  • Audit periodically. Review the token list in Settings → API Tokens and delete any tokens that are no longer in use.