Authorize with Permanent Token
A permanent token lets you authenticate and authorize your application in Space without having to implement OAuth 2.0 authentication flows. Simply create a new token with a specific access scope, and use it for authentication from wherever you want. Use the permanent token as the
Bearer parameter of the
Authorization request header (see an example).
Note that permanent tokens are inherently less secure than temporary access tokens used in OAuth 2.0 authorization. If security is a concern, we recommend that you register your application in Space and use one of the standard OAuth 2.0 authorization flows.
You can use two types of permanent token for application authorization:
Application permanent token: for authorization on behalf of an application.
Personal permanent token: for authorization on behalf of your user account.
Application permanent tokens
An application permanent token lets an application to authenticate and authorize on behalf of itself. The scope of the token corresponds to the permissions granted to the application.
To create an application permanent token
In Administration | Applications, open the required application.
Open the Permanent Tokens tab and click New permanent token.
Specify a token name and an expiration date.
Click Create and copy the created token to a secure location. Note that you won't be able to access the token again.
After you create a token, you can Update it (change the name or expiration date) or Revoke it.
Personal permanent tokens
A personal token lets an application to authenticate and authorize on behalf of a user account. Personal tokens only authorize actions that are allowed for the user who the token belongs to. You can further limit the scope of authorized actions when creating a token.
To learn how to obtain a personal token from your profile, see Personal Tokens.
Example of an HTTP request with a permanent token
This HTTP API call uses a permanent token as the
Bearer attribute of the