API Tokens
How personal API tokens are issued, checked and retired.
Personal API tokens authenticate requests to /api/v1. Each token belongs to
exactly one workspace and acts on behalf of the member who created it.
Lifecycle
1. Creation
- Only members whose role includes Manage API tokens can create tokens (owners, admins, members — not viewers).
- Every requested ability must be permitted by the creator's current role.
- An optional expiry must be in the future.
- Pingi generates
pingi_+ 40 random characters. The response shows this once. Pingi stores only:- a SHA-256 hash of the token (used for lookup),
- the last four characters (so you can recognise it in lists),
- name, abilities, expiry, creator and workspace.
- The creation is written to the audit log — without the token.
2. Use
Send Authorization: Bearer pingi_…. On every request Pingi:
- hashes the presented value and looks it up;
- rejects it unless it is unrevoked, unexpired, and its creator is still a member of the token's workspace;
- scopes the whole request to that one workspace — records of other workspaces resolve as not found;
- requires the endpoint's ability on the token and the matching permission in the creator's current role;
- applies the workspace plan's per-token rate limit;
- records last-used time and IP (at most once a minute).
Changing the creator's role never widens a token: promotion adds no abilities the token lacks, and demotion immediately removes the power of abilities the new role no longer allows.
3. End of life
A token stops working the moment any of these happens:
| Event | Effect |
|---|---|
| Revoked by its creator, or by an owner/admin | revoked_at set; row kept for the audit trail |
| Expiry passes | Rejected from then on |
| Creator leaves or is removed from the workspace | All their tokens for that workspace are revoked |
| Creator's user account is deleted | Their tokens are deleted |
Where tokens never appear
- Database: hashes only.
- Application logs, the audit log and API responses (including the token-introspection endpoint): never the raw token.
- Request inspection (Telescope): the
Authorizationheader and one-time secrets in responses are masked in every environment.