How to Create and Manage API Tokens
Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.
An API token lets a script, a tool or an AI assistant call the CoCoCo API as you. It carries your permissions — whatever you may do, the token may do. For an integration that should have its own, narrower rights, use a service account instead (see Service Accounts).
Before you start: you need the permission to create, see and revoke your tokens (apitoken:write, apitoken:list, apitoken:revoke).
Create a token
Section titled “Create a token”- Click your name in the top right corner and choose API Tokens.
- Under Create New Token, enter a Token name that says what it is for, for example
Claude DesktoporCI pipeline. - Expiration (optional) takes a date and time. If you leave it empty, the token stays valid until you revoke it.
- Click Create token. The box New token created shows the token. It is shown only once: copy it now. When you leave the page, the token stays in the list, but without its value.
Use a token
Section titled “Use a token”Send it in the Authorization header of every request:
Authorization: Bearer <your-token>The panel MCP Connection on the same page shows what an AI assistant needs: the Endpoint URL (your instance address followed by /mcp), the Transport (Streamable HTTP, JSON mode) and the Authentication header. Any active token works there.
Revoke a token
Section titled “Revoke a token”- Under Your tokens, click Revoke next to the token.
- Confirm Revoke this API token? This action cannot be undone. with Revoke.
From then on the token is refused.
Good practice
Section titled “Good practice”- One token per tool or integration, named after it — then you can revoke exactly one.
- Set an expiration for anything temporary.
- Never share a token: it acts with your permissions.