API tokens
An API token is the proof that the CLI, scripts and CI send with each request.
A program sends its token in a header with each request.
The CLI, scripts and CI prove their identity with an API token. A token is fy_ and then 40 hex characters.
Create a token
In the dashboard, open Server → Account. Give the token a name. An expiry is optional.
The dashboard shows the token one time, when you create it. The server stores only its SHA-256 hash. The list shows the last 4 characters of each token and the time of its last use.
Send a token
curl -H "Authorization: Bearer $FERRY_TOKEN" http://127.0.0.1:7878/api/v1/servicesA token has full access. Read What a token can do.
The header comes first: Authorization: Bearer <token>. ?access_token= works on GET requests only. It is for EventSource streams in a browser, which cannot set a header.
The request log of ferryd records paths without their query string.