FerryDocs
Getting startedInstallation

API tokens

The CLI, scripts and CI prove who they are with an API token.

Edit on GitHub
CLItoken from loginCI, scriptsa named tokenServer scriptsthe server tokenAPIBearer fy_…
Each program sends its token with each request

The dashboard signs in with the account. All other programs send an : fy_, then 40 hex characters.

HTTP header
Authorization: Bearer <token>

Three types of token

TokenSourceUse
The token of a terminalferry login asks for one. You approve the request in the dashboard.The CLI on your machine
A named tokenServer → Account → API tokens in the dashboard. It has a name and an optional expiry. The dashboard shows it one time., scripts and machines without a browser
The <data-dir>/api_token (mode 0600). ferryd makes it at the first start and uses it again at each start.Scripts on the server

Use the server token

Terminal
# On the server itself, without logging in
export FERRY_TOKEN="$(cat ferry-data/api_token)"
ferry services

A token is as strong as a root password

An API token can use the full API. But it cannot manage the account, its sessions or its tokens. Do not commit a token. Revoke each token that you do not use. See Security model.

On this page