Skip to content
Back to Knowledge Base

How to Create and Manage API Tokens

Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version.

An API token lets a script, a tool or an AI assistant call the CoCoCo API as you. It carries your permissions — whatever you may do, the token may do. For an integration that should have its own, narrower rights, use a service account instead (see Service Accounts).

Before you start: you need the permission to create, see and revoke your tokens (apitoken:write, apitoken:list, apitoken:revoke).

  1. Click your name in the top right corner and choose API Tokens.
  2. Under Create New Token, enter a Token name that says what it is for, for example Claude Desktop or CI pipeline.
  3. Expiration (optional) takes a date and time. If you leave it empty, the token stays valid until you revoke it.
  4. Click Create token. The box New token created shows the token. It is shown only once: copy it now. When you leave the page, the token stays in the list, but without its value.

Send it in the Authorization header of every request:

Authorization: Bearer <your-token>

The panel MCP Connection on the same page shows what an AI assistant needs: the Endpoint URL (your instance address followed by /mcp), the Transport (Streamable HTTP, JSON mode) and the Authentication header. Any active token works there.

  1. Under Your tokens, click Revoke next to the token.
  2. Confirm Revoke this API token? This action cannot be undone. with Revoke.

From then on the token is refused.

  • One token per tool or integration, named after it — then you can revoke exactly one.
  • Set an expiration for anything temporary.
  • Never share a token: it acts with your permissions.