Skip to content

API Tokens ​

Personal Access Tokens (PATs) authenticate scripts, API clients, and the bundled Swagger UI's Authorize dialog - anything non-interactive. People should keep signing in through SSO; tokens exist so automation does not have to.

Issuing and revoking tokens is admin-only, under Settings → API Tokens.

Create a token ​

  1. Click to create a token and give it a name.
  2. Choose what it is for: the organization it acts in and its scopes. The token always acts as you - tokens cannot be minted for other users.
  3. Optionally set an expiry in days. When the server enforces a maximum token lifetime (HEGEMONY_PAT_MAX_LIFETIME_DAYS), leaving the expiry unset applies that maximum, and a longer expiry is rejected; only when no maximum is configured does an unset expiry mean the token never expires.
  4. Copy the token immediately. The plaintext - recognizable by its hgm_pat_ prefix - is shown exactly once. Hegemony stores only a hash; the list identifies tokens by their name and a short non-secret prefix.

Use the token as a bearer credential:

text
Authorization: Bearer hgm_pat_...

Revoke a token ​

Open the token in the list and revoke it. Revocation takes effect on the next request; create a new token instead of trying to recover a lost plaintext.

Released as open source under the AGPL-3.0-or-later license. Development is sponsored by Rexonix s.r.o.. Contact — [email protected].