Access Token
What it is
Token is the system-level access token generated by the user in Personal Center → Access Token. It uses a UUID format and calls /api/* admin-class endpoints.
It is not the same as the Channel API key:
- User Token → calls One API Pro's
/api/*- Channel API key → used by One API Pro to talk to the upstream provider
Where to find it
- Personal Center → Access Token: view, copy, reset
- Admin → API Tokens: list all tokens, adjust quota, disable, delete
- Call logs: every
/api/*call records the issuingtoken_id
Operator-relevant fields
| Field | Meaning | Effect of editing |
|---|---|---|
| Key | UUID string | Old key stops working immediately. |
| Name | Free-text label | No behavior. |
| Owner | Linked to a User | Deleting the user cascades. |
| Status | Enabled / Disabled / Expired / Exhausted | Disabled → API calls 401 immediately. |
remain_quota | Token's own balance | First deduction source; 0 rejects calls. |
quota | Initial quota granted | Recorded only, not deducted. |
| Expires at | Unix seconds / -1 for never | Status flips to "Expired". |
| Allowed models | Empty = unrestricted | Empty allows all; non-empty → other models 403. |
| Allowed subnet | CIDR list | Client IP outside → 403. |
Relationship to User quota
Deduction order:
Token.remain_quotafirst- Then User.quota
- Then Subscription (plan discount applied)
So one user can hold all of these at once:
- Personal balance
- Multiple tokens, each with its own quota
- One active subscription
Useful for project teams / sub-accounts.
Related API
GET /api/user/token— current user's tokenPOST /api/token— create tokenPUT /api/token— update quota / expiry / model allow-listDELETE /api/token/:id— delete token