Skip to content

Access Token ​

What it is ​

Token is the system-level access token generated by the user in Personal Center → Access Token. It uses a UUID format and calls /api/* admin-class endpoints.

It is not the same as the Channel API key:

  • User Token → calls One API Pro's /api/*
  • Channel API key → used by One API Pro to talk to the upstream provider

Where to find it ​

  • Personal Center → Access Token: view, copy, reset
  • Admin → API Tokens: list all tokens, adjust quota, disable, delete
  • Call logs: every /api/* call records the issuing token_id

Operator-relevant fields ​

FieldMeaningEffect of editing
KeyUUID stringOld key stops working immediately.
NameFree-text labelNo behavior.
OwnerLinked to a UserDeleting the user cascades.
StatusEnabled / Disabled / Expired / ExhaustedDisabled → API calls 401 immediately.
remain_quotaToken's own balanceFirst deduction source; 0 rejects calls.
quotaInitial quota grantedRecorded only, not deducted.
Expires atUnix seconds / -1 for neverStatus flips to "Expired".
Allowed modelsEmpty = unrestrictedEmpty allows all; non-empty → other models 403.
Allowed subnetCIDR listClient IP outside → 403.

Relationship to User quota ​

Deduction order:

  1. Token.remain_quota first
  2. Then User.quota
  3. Then Subscription (plan discount applied)

So one user can hold all of these at once:

  • Personal balance
  • Multiple tokens, each with its own quota
  • One active subscription

Useful for project teams / sub-accounts.

  • GET /api/user/token — current user's token
  • POST /api/token — create token
  • PUT /api/token — update quota / expiry / model allow-list
  • DELETE /api/token/:id — delete token