On this page

Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.

8 operations.

GET /api/security/tokens

List all tokens

Operation ID: findAllTokens

Retrieves all tokens. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Tokens retrievedapplication/json: TzTokenListResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

POST /api/security/tokens

Create token

Operation ID: createToken

Creates a new application token and returns its secret. The secret is shown only here and on rotation; it cannot be retrieved again afterwards. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzTokenCreateRequestDto

Responses

StatusDescriptionBody
200Token createdapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

GET /api/security/tokens/{id}

Get token by ID

Operation ID: findTokenById

Retrieves a token by identifier. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1

Responses

StatusDescriptionBody
200Token foundapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

PUT /api/security/tokens/{id}

Update token

Operation ID: updateToken

Updates an existing token’s name, roles and expiry. Does not reissue the secret. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzTokenUpdateRequestDto

Responses

StatusDescriptionBody
200Token updatedapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

DELETE /api/security/tokens/{id}

Delete token

Operation ID: deleteToken

Deletes a token. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Token deletedapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

PUT /api/security/tokens/{id}/disable

Disable token

Operation ID: disableToken

Disables a token. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Token disabledapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

PUT /api/security/tokens/{id}/enable

Enable token

Operation ID: enableToken

Enables a token. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Token enabledapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value

POST /api/security/tokens/{id}/rotate

Rotate token

Operation ID: rotateToken

Issues a new secret for an existing token, keeping its id, name, roles and enabled flag; resets creation from now. expiryDays is required and relative to now: the previous expiry window is not preserved, because the expiry policy is not stored anywhere. Not idempotent: every call mints a different secret. Requires ADMIN role.

Security: bearerAuth

Parameters

NameInRequiredTypeDescription
idpathtruestringToken identifier minLength: 1
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzTokenRotateRequestDto

Responses

StatusDescriptionBody
200Token rotatedapplication/json: TzTokenResponseDto
400Bad Request/: map of any JSON value
404Not Found/: map of any JSON value
409Conflict/: map of any JSON value
Golden 3.0.0 · Published 2026-10-04