`POST /v1/orgs/{org}/api-tokens`.
const url = 'https://api.updawg.net/v1/orgs/example/api-tokens';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"expires_at":"2026-04-15T12:00:00Z","name":"example","scopes":["example"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.updawg.net/v1/orgs/example/api-tokens \ --header 'Content-Type: application/json' \ --data '{ "expires_at": "2026-04-15T12:00:00Z", "name": "example", "scopes": [ "example" ] }'Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
Request Bodyrequired
Section titled “Request Bodyrequired”object
When it stops working. Absent never expires.
What it is for — “terraform”, “CI”. Shown in the list, since the value never is again.
What it may do: any of read, comment, approve, rollout,
jobs, policy, groups, hosts, enrollment, audit,
integrations, as far as your role allows.
Examplegenerated
{ "expires_at": "2026-04-15T12:00:00Z", "name": "example", "scopes": [ "example" ]}Responses
Section titled “Responses”Issued. ⚠️ token is in this response and never again.
The one response that carries the value.
object
The usr_… it acts as.
atk_…. The record, not the credential.
To the minute: written at most once a minute.
The value’s first characters, to recognise it by: upd_AbCdEfGh.
⚠️ Shown once. upd_…, sent as Authorization: Bearer upd_….
Examplegenerated
{ "created_at": "2026-04-15T12:00:00Z", "created_by": "example", "created_by_email": "example", "expires_at": "2026-04-15T12:00:00Z", "id": "example", "last_used_at": "2026-04-15T12:00:00Z", "name": "example", "prefix": "example", "revoked_at": "2026-04-15T12:00:00Z", "scopes": [ "example" ], "token": "example"}No name, no scopes, a scope that is not one or that your role cannot grant, or an expiry in the past.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted for this role, or asked with an API token. Or the plan is not Business or Enterprise: plan-required.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such organization, or not yours — one answer for both.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}