API 토큰 생성
API 토큰 생성 (Create API Token)
사용자 계정에 속한 새 API 토큰을 발급하는 엔드포인트예요. 토큰은 세 가지 수준으로 범위를 좁혀 발급할 수 있는데, 새 토큰에는 항상 조직 범위를 지정하는 게 좋아요.
출처: 문서
본문
Returns a new API token belonging to a user.
토큰은 좁혀지는 순서대로 세 가지 수준의 제한으로 발급할 수 있어요:
- 조직 범위(Organization-scoped) —
organization을 전달해요. 토큰은 그 조직 안의 리소스에만 동작할 수 있어요. - 그룹 범위(Group-scoped) —
organization,group,scopes를 전달해요. 토큰은 조직 안의 한 그룹에 고정되고,scopes에 나열된 작업만 허용돼요. 호출자는 조직의 관리자 또는 소유자여야 해요. - 무제한(Unrestricted) (사용 중단됨) — 요청 본문 없이 호출해요. 토큰은 호출자가 속한 모든 조직에서 동작할 수 있어요. 무제한 토큰은 사용이 중단되었으며 향후 릴리스에서 제거될 예정이에요. 새 토큰에는 항상
organization을 전달하고, 기존 무제한 토큰은 범위가 지정된 토큰으로 교체하세요.
그룹 범위 토큰은 조직의 나머지 부분에는 손대지 못하면서 한 그룹 안에서 데이터베이스를 프로비저닝하고 관리할 수 있게 설계된 자동화용이에요.
응답의 `token`은 다시는 공개되지 않아요. 안전한 곳에 저장하고, 절대 공유하거나 소스 컨트롤에 커밋하지 마세요. **무제한(조직 간) 토큰은 사용이 중단되었으며 향후 릴리스에서 제거될 예정이에요.** 요청 본문에는 최소한 `organization`이라도 포함하세요. ```bash cURL (org-scoped) theme={null} curl -L -X POST https://api.turso.tech/v1/auth/api-tokens/{tokenName} \ -H 'Authorization: Bearer ***' \ -H 'Content-Type: application/json' \ -d '{"organization": "my-org"}' ```curl -L -X POST https://api.turso.tech/v1/auth/api-tokens/{tokenName} \
-H 'Authorization: Bearer ***'
curl -L -X POST https://api.turso.tech/v1/auth/api-tokens/{tokenName} \
-H 'Authorization: Bearer ***' \
-H 'Content-Type: application/json' \
-d '{
"organization": "my-org",
"group": "default",
"scopes": ["read-only"]
}'
curl -L -X POST https://api.turso.tech/v1/auth/api-tokens/{tokenName} \
-H 'Authorization: Bearer ***' \
-H 'Content-Type: application/json' \
-d '{
"organization": "my-org",
"group": "default",
"scopes": ["db:create", "db:configure", "db:mint-token"]
}'
import { createClient } from "@tursodatabase/api";
const turso = createClient({
org: "...",
token: "",
});
const apiToken = await turso.apiTokens.create("my-token");
OpenAPI
openapi: 3.0.1
info:
title: Turso Platform API
description: API description here
license:
name: MIT
version: 0.1.0
servers:
- url: https://api.turso.tech
description: Turso's Platform API
security: []
paths:
/v1/auth/api-tokens/{tokenName}:
post:
summary: Create API Token
description: >-
Returns a new API token belonging to a user.
The token can be minted at three levels of restriction, in increasing
order of narrowness:
- **Organization-scoped** — pass `organization`. The token can only act
on resources inside that organization.
- **Group-scoped** — pass `organization`, `group`, and `scopes`. The
token is pinned to a single group inside the organization and only the
operations listed in `scopes` are allowed. The caller must be an admin
or owner of the organization.
- **Unrestricted** *(deprecated)* — no request body. The token can act
on every organization the caller belongs to. **Unrestricted tokens are
deprecated and will be removed in a future release.** Always pass
`organization` for new tokens and rotate existing unrestricted tokens to
scoped tokens.
Group-scoped tokens are designed for automations that should be able to
provision and manage databases inside a single group without being able
to touch the rest of the organization.
operationId: createAPIToken
parameters:
- $ref: '#/components/parameters/tokenName'
requestBody:
description: >-
Optional restriction for the token. Omit the body for an unrestricted
token, pass `organization` alone for an org-scoped token, or pass
`organization` + `group` + `scopes` for a group-scoped token.
required: false
content:
application/json:
schema:
type: object
properties:
organization:
type: string
description: >-
The organization slug to restrict this token to. Required
when `group` is set.
example: my-org
group:
type: string
description: >-
The group name (inside `organization`) to restrict this
token to. Requires `organization` and a non-empty `scopes`
list.
example: default
scopes:
type: array
items:
type: string
enum:
- read
- db:create
- db:delete
- db:configure
- db:mint-token
- db:rotate-creds
- group:configure
- group:mint-token
- group:rotate-creds
- read-only
- full-access
description: >-
Permissions to grant a group-scoped token. Each entry is
either an individual scope or one of the presets `read-only`
(expands to `read`) and `full-access` (expands to every
scope). Required and must be non-empty when `group` is set.
`db:mint-token` lets the token issue new SQL credentials;
`db:rotate-creds` invalidates every existing SQL token for
the database — they are deliberately separate because
rotation is destructive.
example:
- db:create
- db:configure
- db:mint-token
responses:
'200':
description: Successful response
content:
application/json:
schema:
properties:
name: 1003799d-19af-4e04-9f91-bd42a76d9d41
id: 8624135b-a36a-42d5-8159-9c5d48f8e393
token:
type: string
description: >-
The actual token contents as a JWT. This is used with the
`Bearer` header, see [Authentication](/authentication) for
more details. **This token is never revealed again.**
example: ...
components:
parameters:
tokenName:
name: tokenName
in: path
required: true
schema:
type: string
description: The name of the api token.
더 알아보기 (Learn more)
- API 토큰 목록 — 발급된 토큰을 확인해요.
- API 토큰 폐기 — 더 이상 필요 없는 토큰을 무효화해요.
- 인증(Authentication) — Bearer 헤더 사용법을 살펴봐요.
- 응답 코드 — 오류 코드 의미를 확인해요.