On this page
Access tokens API
Generated Golden API operations for Access tokens.
Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.
8 operations.
GET /api/security/tokens
List all tokens
Operation ID: findAllTokens
Retrieves all tokens. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Tokens retrieved | application/json: TzTokenListResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
POST /api/security/tokens
Create token
Operation ID: createToken
Creates a new application token and returns its secret. The secret is shown only here and on rotation; it cannot be retrieved again afterwards. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzTokenCreateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token created | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
GET /api/security/tokens/{id}
Get token by ID
Operation ID: findTokenById
Retrieves a token by identifier. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token found | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
PUT /api/security/tokens/{id}
Update token
Operation ID: updateToken
Updates an existing token’s name, roles and expiry. Does not reissue the secret. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzTokenUpdateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token updated | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
DELETE /api/security/tokens/{id}
Delete token
Operation ID: deleteToken
Deletes a token. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token deleted | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
PUT /api/security/tokens/{id}/disable
Disable token
Operation ID: disableToken
Disables a token. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token disabled | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
PUT /api/security/tokens/{id}/enable
Enable token
Operation ID: enableToken
Enables a token. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token enabled | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
POST /api/security/tokens/{id}/rotate
Rotate token
Operation ID: rotateToken
Issues a new secret for an existing token, keeping its id, name, roles and enabled flag; resets creation from now. expiryDays is required and relative to now: the previous expiry window is not preserved, because the expiry policy is not stored anywhere. Not idempotent: every call mints a different secret. Requires ADMIN role.
Security: bearerAuth
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
id | path | true | string | Token identifier minLength: 1 |
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzTokenRotateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Token rotated | application/json: TzTokenResponseDto |
400 | Bad Request | /: map of any JSON value |
404 | Not Found | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |