Skip to main content
POST
Create a personal API token

Authorizations

Authorization
string
header
required

Personal API token, sent as Authorization: Bearer <SANDYWP_API_KEY>. Obtain one from the dashboard account menu (API keys), sandywp auth login, or POST /api/account/tokens. A missing or invalid token returns 401 auth_required. Scoped OAuth tokens are limited to the Imports family and GET /api/account/me; see the top-level conventions.

Headers

X-SandyWP-Workspace
string

Selects which of the caller's workspaces to act in, for accounts belonging to more than one (legacy alias: X-SandyWP-Organization). Defaults to the caller's own personal workspace when omitted. Every id in this API (sandboxes, Templates, repositories) is scoped to a single workspace, so this header changes which set of resources is visible.

Body

application/json
label
string

Optional label. Blank values become null.

Maximum string length: 200

Response

The one-time plaintext token and its persistent metadata.

token
string
required

Plaintext bearer token. It cannot be retrieved again.

apiToken
object
required

Persistent token metadata. Plaintext token material is intentionally absent.