← Back

Scoped API tokens

New

API tokens can now carry scoped permissions like accounts:read. You define scopes and their actions in config/initializers/api_tokens.rb, so they can match your own resources, for example "blog_posts" => %w[read publish archive].

Existing and new tokens are granted every permission, so current behavior is unchanged.