Files
zkldi_Tachi/old-docs/docs/api/routes/api-tokens.md
T
zk e363bd2532 docs: migrate from mkdocs to mdbook (#1558)
* docs: migrate from mkdocs to mdbook

- Rename old mkdocs docs/ to old-docs/ for reference
- Set up new docs/ with mdbook (book.toml + src/ tree)
- Mirror full nav structure from mkdocs.yml into SUMMARY.md
- Add Justfile-docs with docs-serve, docs-build, docs-check, docs-install recipes
- Import Justfile-docs from root Justfile
- Rewrite .github/workflows/docs.yml: build step uses taiki-e/install-action
  to install mdbook, split into separate build + deploy jobs, PR builds
  run the check step too

* ci(docs): pin actions to SHAs, install mdbook via release binary

* ci(docs): install mdbook from apt instead of curling a release binary

* dev: replace mkdocs python stack with mdbook in dev image

* ci(docs): apt only works on Debian; restore release binary install for Ubuntu CI

* docs: fix duplicate file entries in SUMMARY.md

* docs: remove docs-install recipe

* docs: remove site-url from book.toml to fix asset loading

* dev: install mdbook from upstream release binary, not Debian apt

The Debian package (0.4.x+ds) strips bundled font assets, leaving the
built site without fonts/fonts.css. Use the upstream tarball (same as CI)
so the theme is complete. Handles x86_64 and aarch64.

* docs: vendor mdbook tarballs in dev/mdbook/, install from there

Dockerfile.dev uses COPY + tar to install the right arch at build time.
CI extracts the x86_64 tarball directly from the checkout.
No network access required for either — and no stripped-fonts Debian package.

* fix: unwritten
2026-05-22 20:43:07 +01:00

2.0 KiB

API Token Management

These endpoints relate to managing a users created API Tokens. These tokens are likely to be generated from an OAuth2 integration, but in the future users may be able to create their own API Keys manually.

!!! note All of the below endpoints require Self Key level authentication. You cannot interact with these endpoints with Bearer auth.


Retrieve all API Tokens

GET /api/v1/users/:userID/api-tokens

Parameters

None.

Response

| Property | Type | Description | | :: | :: | :: | | <body> | APIKeyDocument | An array of APIKeyDocuments that belong to this user. |

Example

Request

GET /api/v1/users/1/api-tokens

Response

[{
	"identifier": "Fervidex Token",
	"token": "foobar",
	"permissions": {"submit_score": true},
	"userID": 1,
	"fromAPIClient": "FERVIDEX_OA2_CLIENT_ID"
}]

Delete a specific token.

DELETE /api/v1/users/:userID/api-token/:token

Parameters

None.

Response

Empty Object.

Example

Request

DELETE /api/v1/users/1/api-token/foobar

Response

{}

Create an API Token

POST /api/v1/users/:userID/api-tokens/create

Parameters

| Property | Type | Description | | :: | :: | :: | | permissions | Array<String> | An array of permissions you wish the key to have. | | clientID | String | Alternatively, you can pass the clientID of an OAuth2 Client. This will select permissions based on what that client wants. | | identifier | String | A humanised identifier for what the string was from. Necessary if using permissions. Filled out for you if using clientID.

!!! info If using ClientID for permissions, the clientID will be pinned to the token you've created as fromAPIClient. You can only have one API Token per OAuth2 client, and will get a 409 if you repeat the request.

Response

| Property | Type | Description | | :: | :: | :: | | <body> | APITokenDocument | The API Token you created. |