AirMDR Token API

Endpoints to manage tokens

Operations 4

POST /users/tokens create API token #
GET /users/tokens list all API Tokens created by a user #
POST /users/tokens/slack Issues or returns the API token used to authenticate actions when the user… #
DELETE /users/tokens/{token_id} delete an API Token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/airmdr:airmdr-token-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

airmdr-token-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: User Management Service Token API
  version: 1.0.0
  description: Endpoints to manage tokens
servers:
- url: /airmdrapi
tags:
- name: Token
  description: Endpoints to manage tokens
paths:
  /users/tokens:
    post:
      tags:
      - Token
      operationId: createAPITokenForUserAPI
      summary: create API token
      description: Creates API Token for the Requestor. Api tokens are user level and permissions associated with a token are the same as that of the user who created that token. This action can only be performed by superadmin or admin accounts.
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: Organization-ID
        in: header
        description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: X-Request-ID
        in: header
        description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
      - name: return_active_token_if_exists
        in: query
        description: If true, returns an existing active token instead of creating a new one. Defaults to false.
        schema:
          type: boolean
          default: false
      security:
      - SessionCookie: []
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: Name of the Token to be created
                organization_id:
                  type: string
                  description: Optional. Scope the token to a specific organization that the requesting user can access (one they can switch session context into). Must be an accessible organization for the requestor, otherwise the request is rejected with 403. If omitted, the token is scoped to the requestor's own organization.
              required:
              - name
      responses:
        '200':
          description: api token creation successful
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateAPITokenResponse'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/403Error'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
    get:
      tags:
      - Token
      operationId: listTokensForUserAPI
      summary: list all API Tokens created by a user
      description: List all API Tokens created by a User. This action can only be performed by superadmin or admin accounts.
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: Organization-ID
        in: header
        description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: X-Request-ID
        in: header
        description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
      - name: user_id
        in: query
        description: The User ID for whom to fetch tokens. If not provided, fetches tokens for the authenticated user (User-ID header).
        schema:
          type: string
        required: false
      security:
      - SessionCookie: []
      responses:
        '200':
          description: fetched API Tokens successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListAPITokensResponse'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/403Error'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /users/tokens/slack:
    post:
      tags:
      - Token
      operationId: createAPITokenForSlackWorkflowAPI
      summary: Issues or returns the API token used to authenticate actions when the user…
      description: Creates and returns a new API token—used for processing user actions triggered by Slack mentions—if one does not already exist for the authenticated user; otherwise returns the existing token to ensure consistent authentication during Slack-initiated workflows.
      parameters:
      - name: User-ID
        in: header
        description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: Organization-ID
        in: header
        description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: X-Request-ID
        in: header
        description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
      security:
      - SessionCookie: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAPITokenForSlackWorkflowRequest'
      responses:
        '200':
          description: api token creation successful
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateAPITokenForSlackWorkflowResponse'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/403Error'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
  /users/tokens/{token_id}:
    delete:
      tags:
      - Token
      operationId: deleteTokenAPI
      summary: delete an API Token
      description: Deletes API Token. Only creator can delete their token. This action can only be performed by superadmin or admin accounts.
      parameters:
      - name: token_id
        in: path
        description: The id of the token to be deleted
        required: true
        schema:
          type: string
      - name: User-ID
        in: header
        description: The User ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: Organization-ID
        in: header
        description: The Organization ID of the requestor. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
        required: true
      - name: X-Request-ID
        in: header
        description: The ID associated with the request. If requests are made through API Gateway, this header will be pre filled.
        schema:
          type: string
      security:
      - SessionCookie: []
      responses:
        '200':
          description: api token deletion successful
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Success'
        '403':
          description: forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/403Error'
        default:
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    GetAPITokenResponse:
      type: object
      required:
      - token_id
      - name
      - created_at
      properties:
        token_id:
          type: string
        encrypted_token:
          type: string
        encrypted_version_id:
          type: string
        name:
          type: string
        created_at:
          type: integer
          format: int64
        last_used_at:
          type: integer
          format: int64
        organization_id:
          type: string
    CreateAPITokenForSlackWorkflowResponse:
      type: object
      required:
      - message
      - data
      properties:
        message:
          type: string
        data:
          $ref: '#/components/schemas/GetAPITokenResponse'
    ListAPITokensResponse:
      type: object
      required:
      - message
      - data
      - total
      properties:
        message:
          type: string
        data:
          type: array
          items:
            $ref: '#/components/schemas/GetAPITokenResponse'
        total:
          type: integer
    CreateAPITokenResponse:
      type: object
      required:
      - token_id
      - name
      - token
      - created_at
      properties:
        token_id:
          type: string
        name:
          type: string
        token:
          type: string
          description: The token created for the user
        created_at:
          type: integer
          format: int64
        last_used_at:
          type: integer
          format: int64
    CreateAPITokenForSlackWorkflowRequest:
      type: object
      required:
      - user_id
      - organization_id
      properties:
        user_id:
          type: string
          description: The User ID of the user to create the Slack token for.
        organization_id:
          type: string
          description: The Organization ID of the organization to create the Slack token for.
    403Error:
      type: object
      properties:
        message:
          type: string
          const: User does not have permission to perform this action
    Error:
      type: object
      required:
      - message
      properties:
        message:
          type: string
          description: user friendly error message
    Success:
      type: object
      required:
      - message
      properties:
        message:
          type: string
          description: user friendly message
  securitySchemes:
    SessionCookie:
      type: apiKey
      in: cookie
      name: Session
x-tagGroups:
- name: Included APIs
  tags:
  - Organization
  - User
  - User Group
  - Token
  - Permission