Getting startedInstallation
API tokens
The CLI, scripts and CI prove who they are with an API token.
The dashboard signs in with the account. All other programs send an API token: fy_, then 40 hex characters.
Authorization: Bearer <token>Three types of token
| Token | Source | Use |
|---|---|---|
| The token of a terminal | ferry login asks for one. You approve the request in the dashboard. | The CLI on your machine |
| A named token | Server → Account → API tokens in the dashboard. It has a name and an optional expiry. The dashboard shows it one time. | CI, scripts and machines without a browser |
| The server token | <data-dir>/api_token (mode 0600). ferryd makes it at the first start and uses it again at each start. | Scripts on the server |
Use the server token
# On the server itself, without logging in
export FERRY_TOKEN="$(cat ferry-data/api_token)"
ferry servicesA token is as strong as a root password
An API token can use the full API. But it cannot manage the account, its sessions or its tokens. Do not commit a token. Revoke each token that you do not use. See Security model.
Server → Account lists the first two types. It shows the last 4 characters of each token and its last use. You can revoke a token there immediately.
The server token is different. Ferry does not print it and does not list it in the dashboard. You cannot revoke it there.
Start ferryd with --api-token or FERRY_API_TOKEN. This value comes before the file.