Skip to content

client.tokens

client.tokens — the tokens operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
cursor: str | None = None,
limit: int | None = None,
timeout: float | None = None,
) -> ApiTokenPage

List API keys. GET /v1/tokens

Newest first. Never returns secrets. Tenant admins only.

mint(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> MintTokenResult

Mint an API key. POST /v1/tokens

An API key is a service account in the tenant, with a role and explicit capabilities. Returns the plaintext token exactly once. Tenant admins only; a caller can only grant capabilities it holds. Only mounted when the deployment supplies a TokenAdmin.

get(*, timeout: float | None = None) -> ApiToken

Read an API key. GET /v1/tokens/{tokenId}

Never returns the secret. Tenant admins only.

revoke(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
) -> RevokeTokenResult

Revoke an API key. POST /v1/tokens/{tokenId}/revoke

Takes effect on the next request. Tenant admins only.

mint_public(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> MintPublicRunTokenResult

Mint a public run token. POST /v1/tokens/public

A short-lived, read-only token for up to 50 runs (and their descendants), to hand to a browser: it can only call GET /v1/runs/{runId}/progress and GET /v1/runs/{runId}/progress/stream. Stateless: it cannot be revoked one by one, so keep lifetimes short. Mounted when the deployment issues public run tokens.