Access Token
When the browser session isn't available but scripts / CI need to call admin APIs — use an Access Token.
What is it
A UUID string you generate in your personal center. It lets you call One API Pro's /api/* admin endpoints (your profile, your logs, etc.) without a browser session.
Common use cases:
- Automation scripts
- CI / server-side jobs
- Anywhere browser cookies aren't available
Difference from API Key
| Item | Access Token | API Key (sk-…) |
|---|---|---|
| What | UUID string | sk--prefixed random string |
| Calls | /api/* admin | /v1/* OpenAI-compatible |
| Auth header | Authorization: <uuid> | Authorization: Bearer sk-… |
| Generated by | You (personal center) | You (tokens page) |
| Revocation | Regenerate | Delete |
Access Token manages One API Pro itself; API Key lets others use One API Pro to call models.
Generate
Web UI
- Log in
- Top-right avatar → Personal Center
- Find the Access Token section
- Click "Generate"
- Copy immediately — refresh and it's gone
Via API (if you're already logged in elsewhere)
bash
curl http://localhost:3000/api/user/token -b cookies.txtReturns the new UUID.
Use
Put the UUID in the Authorization header (no Bearer prefix):
bash
curl http://localhost:3000/api/user/self \
-H "Authorization: <your_access_token>"Returns the current user info on success.
Regenerate (revoke the old one)
Personal Center → Access Token → "Generate" again. You get a new UUID; the old one is immediately invalid.
Use when: you suspect a leak, you want to revoke, or for periodic rotation.
Safety
| Tip | Why |
|---|---|
| Treat like a password | Anyone with it gets full /api/* access |
| Don't commit to git | History is forever |
| Different token per environment | Smaller blast radius |
| Regenerate on suspected leak | Old one stops working immediately |
| Use a dedicated token in CI | Don't reuse your personal one |
FAQ
- "Generate" button does nothing: refresh and retry; or check for browser pop-up blockers
- Old token still works after regeneration: cache takes a few seconds — wait
- Can I share it with someone else: No. Access Token is tied to your account — sharing = handing over your account
Related
- Profile — password, email
- My Orders
- API Reference