Create API token
Creates a project API token for server-side authentication to SignalWire REST APIs, with only the permission categories supplied in the request. Use it when a backend service needs durable project credentials; client applications should receive a service-specific token such as a Chat Token, PubSub Token, Room Token, or Subscriber Token instead. The token remains usable until you delete it or remove required permissions.
The Compatibility API exposes the same project tokens through its account-scoped route. Use Generate a new API Token for that request format.
The response is the only place the token secret is returned. Store it securely; no later request, including Update API token, can read it back.
With a project API token, the new token belongs to the authenticated project, or to one of its subprojects when subproject_id is given; project_id is ignored. With a Personal access token, project_id is required and names the project the token is created for, which is how a root project created with Create a project gets its first credential.
Permissions
With a project API token, the token must have the following scope(s) enabled to make a successful request: Management.
With a Personal access token there are no scopes. The token holder must be an owner or admin of the space, and the request reaches only the projects the holder is enabled for, plus their subprojects.
Token Permissions
You must set the functions allowed by this API Token by selecting which types of requests this API Token is allowed to make.
Valid options are: calling, chat, datasphere, fax, management, messaging, numbers, pubsub, storage, tasking, and video
Authentication
SignalWire Basic Authentication using Project ID and API Token.
The client sends HTTP requests with the Authorization header containing the word Basic followed by a space and a base64-encoded string of project_id:token. The project ID will be used as the username and the API token as the password.
Example:
Authorization: Basic base64(project_id:token)
Personal access token authentication for space-wide administration.
Send HTTP Basic auth with an empty username and the Personal access token as
the password. A Personal access token carries your own authority rather than a
project's: it is created from your user menu in the Dashboard, is prefixed
pat_, and has no scopes. The holder must be an owner or admin of the space
named by the subdomain, and the token acts only on that space.
Example:
Authorization: Basic base64(:pat_...)
Request
Personal access token only. The project to create the token for. Required with a
Personal access token and must name a project the token holder can reach
(invalid_project_id). Ignored with a project API token, which creates the token on
its own project.
The unique identifier of the subproject you would like to create a token for. The subproject passed must be a child of the project used to authenticate the request, or of project_id when authenticating with a Personal access token.
Response
The API token that can be used along with the project ID for basic authentication. It is returned only in this response and cannot be retrieved again; store it securely.