Skip to content

Access Token ​

When the browser session isn't available but scripts / CI need to call admin APIs — use an Access Token.

What is it ​

A UUID string you generate in your personal center. It lets you call One API Pro's /api/* admin endpoints (your profile, your logs, etc.) without a browser session.

Common use cases:

  • Automation scripts
  • CI / server-side jobs
  • Anywhere browser cookies aren't available

Difference from API Key ​

ItemAccess TokenAPI Key (sk-…)
WhatUUID stringsk--prefixed random string
Calls/api/* admin/v1/* OpenAI-compatible
Auth headerAuthorization: <uuid>Authorization: Bearer sk-…
Generated byYou (personal center)You (tokens page)
RevocationRegenerateDelete

Access Token manages One API Pro itself; API Key lets others use One API Pro to call models.

Generate ​

Web UI

  1. Log in
  2. Top-right avatar → Personal Center
  3. Find the Access Token section
  4. Click "Generate"
  5. Copy immediately — refresh and it's gone

Via API (if you're already logged in elsewhere)

bash
curl http://localhost:3000/api/user/token -b cookies.txt

Returns the new UUID.

Use ​

Put the UUID in the Authorization header (no Bearer prefix):

bash
curl http://localhost:3000/api/user/self \
  -H "Authorization: <your_access_token>"

Returns the current user info on success.

Regenerate (revoke the old one) ​

Personal Center → Access Token → "Generate" again. You get a new UUID; the old one is immediately invalid.

Use when: you suspect a leak, you want to revoke, or for periodic rotation.

Safety ​

TipWhy
Treat like a passwordAnyone with it gets full /api/* access
Don't commit to gitHistory is forever
Different token per environmentSmaller blast radius
Regenerate on suspected leakOld one stops working immediately
Use a dedicated token in CIDon't reuse your personal one

FAQ ​

  • "Generate" button does nothing: refresh and retry; or check for browser pop-up blockers
  • Old token still works after regeneration: cache takes a few seconds — wait
  • Can I share it with someone else: No. Access Token is tied to your account — sharing = handing over your account