API Tokens
Personal Access Tokens (PATs) authenticate scripts, API clients, and the bundled Swagger UI's Authorize dialog - anything non-interactive. People should keep signing in through SSO; tokens exist so automation does not have to.
Issuing and revoking tokens is admin-only, under Settings → API Tokens.
Create a token
- Click to create a token and give it a name.
- Choose what it is for: the organization it acts in and its scopes. The token always acts as you - tokens cannot be minted for other users.
- Optionally set an expiry in days. When the server enforces a maximum token lifetime (
HEGEMONY_PAT_MAX_LIFETIME_DAYS), leaving the expiry unset applies that maximum, and a longer expiry is rejected; only when no maximum is configured does an unset expiry mean the token never expires. - Copy the token immediately. The plaintext - recognizable by its
hgm_pat_prefix - is shown exactly once. Hegemony stores only a hash; the list identifies tokens by their name and a short non-secret prefix.
Use the token as a bearer credential:
text
Authorization: Bearer hgm_pat_...Revoke a token
Open the token in the list and revoke it. Revocation takes effect on the next request; create a new token instead of trying to recover a lost plaintext.
Related
- Secrets - store tokens your flows need as secrets, never in variables.
- Permissions reference - what token scopes map to.