Digital Ocean SSH Keys API
Manage SSH keys available on your account.
Manage SSH keys available on your account.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/digital-ocean-ssh-keys-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: DigitalOcean SSH Keys API
version: '2.0'
description: '# Introduction
The DigitalOcean API allows you to manage Droplets and resources within the
DigitalOcean cloud in a simple, programmatic way using conventional HTTP requests.'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
contact:
name: DigitalOcean API Team
email: api-engineering@digitalocean.com
termsOfService: https://www.digitalocean.com/legal/terms-of-service-agreement/
servers:
- url: https://api.digitalocean.com
description: production
security:
- bearer_auth: []
tags:
- name: SSH Keys
description: Manage SSH keys available on your account.
paths:
/v2/account/keys:
get:
operationId: sshKeys_list
summary: List All SSH Keys
description: To list all of the keys in your account, send a GET request to `/v2/account/keys`. The response will be a JSON object with a key set to `ssh_keys`. The value of this will be an array of ssh_key objects, each of which contains the standard ssh_key attributes.
tags:
- SSH Keys
parameters:
- $ref: '#/components/parameters/per_page'
- $ref: '#/components/parameters/page'
responses:
'200':
$ref: '#/components/responses/sshKeys_all'
'401':
$ref: '#/components/responses/unauthorized'
'429':
$ref: '#/components/responses/too_many_requests'
'500':
$ref: '#/components/responses/server_error'
default:
$ref: '#/components/responses/unexpected_error'
x-codeSamples:
- lang: cURL
source: "curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"Authorization: Bearer $DIGITALOCEAN_TOKEN\" \\\n \"https://api.digitalocean.com/v2/account/keys\""
- lang: Go
source: "import (\n \"context\"\n \"os\"\n\n \"github.com/digitalocean/godo\"\n)\n\nfunc main() {\n token := os.Getenv(\"DIGITALOCEAN_TOKEN\")\n\n client := godo.NewFromToken(token)\n ctx := context.TODO()\n\n opt := &godo.ListOptions{\n Page: 1,\n PerPage: 200,\n }\n\n keys, _, err := client.Keys.List(ctx, opt)\n}"
- lang: Ruby
source: 'require ''droplet_kit''
token = ENV[''DIGITALOCEAN_TOKEN'']
client = DropletKit::Client.new(access_token: token)
ssh_keys = client.ssh_keys.all
ssh_keys.each'
- lang: Python
source: 'import os
from pydo import Client
client = Client(token=os.environ.get("DIGITALOCEAN_TOKEN"))
resp = client.ssh_keys.list()'
security:
- bearer_auth:
- ssh_key:read
post:
operationId: sshKeys_create
summary: Create a New SSH Key
description: To add a new SSH public key to your DigitalOcean account, send a POST request to `/v2/account/keys`. Set the `name` attribute to the name you wish to use and the `public_key` attribute to the full public key you are adding.
tags:
- SSH Keys
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/sshKeys'
responses:
'201':
$ref: '#/components/responses/sshKeys_new'
'401':
$ref: '#/components/responses/unauthorized'
'429':
$ref: '#/components/responses/too_many_requests'
'500':
$ref: '#/components/responses/server_error'
default:
$ref: '#/components/responses/unexpected_error'
x-codeSamples:
- lang: cURL
source: "curl -X POST \\\n -H \"Content-Type: application/json\" \\\n -H \"Authorization: Bearer $DIGITALOCEAN_TOKEN\" \\\n -d '{\"name\":\"My SSH Public Key\",\"public_key\":\"ssh-rsa AEXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V example\"}' \\\n \"https://api.digitalocean.com/v2/account/keys\" "
- lang: Go
source: "import (\n \"context\"\n \"os\"\n\n \"github.com/digitalocean/godo\"\n)\n\nfunc main() {\n token := os.Getenv(\"DIGITALOCEAN_TOKEN\")\n\n client := godo.NewFromToken(token)\n ctx := context.TODO()\n\n createRequest := &godo.KeyCreateRequest{\n Name: \"My SSH Public Key\",\n PublicKey: \"ssh-rsa AEXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V example\",\n }\n\n transfer, _, err := client.Keys.Create(ctx, createRequest)\n}"
- lang: Ruby
source: "require 'droplet_kit'\ntoken = ENV['DIGITALOCEAN_TOKEN']\nclient = DropletKit::Client.new(access_token: token)\n\nssh_key = DropletKit::SSHKey.new(\n name: 'My SSH Public Key',\n public_key: 'ssh-rsa AEXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V example'\n)\nclient.ssh_keys.create(ssh_key)"
- lang: Python
source: "import os\nfrom pydo import Client\n\nclient = Client(token=os.environ.get(\"DIGITALOCEAN_TOKEN\"))\n\nreq = {\n \"public_key\": \"ssh-rsa AEXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V example\",\n \"name\": \"My SSH Public Key\"\n}\n\nresp = client.ssh_keys.create(body=req)"
security:
- bearer_auth:
- ssh_key:create
/v2/account/keys/{ssh_key_identifier}:
get:
operationId: sshKeys_get
summary: Retrieve an Existing SSH Key
description: 'To get information about a key, send a GET request to `/v2/account/keys/$KEY_ID` or `/v2/account/keys/$KEY_FINGERPRINT`.
The response will be a JSON object with the key `ssh_key` and value an ssh_key object which contains the standard ssh_key attributes.'
tags:
- SSH Keys
parameters:
- $ref: '#/components/parameters/ssh_key_identifier'
responses:
'200':
$ref: '#/components/responses/sshKeys_existing'
'401':
$ref: '#/components/responses/unauthorized'
'404':
$ref: '#/components/responses/not_found'
'429':
$ref: '#/components/responses/too_many_requests'
'500':
$ref: '#/components/responses/server_error'
default:
$ref: '#/components/responses/unexpected_error'
x-codeSamples:
- lang: cURL
source: "curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"Authorization: Bearer $DIGITALOCEAN_TOKEN\" \\\n \"https://api.digitalocean.com/v2/account/keys/512190\" "
- lang: Go
source: "import (\n \"context\"\n \"os\"\n\n \"github.com/digitalocean/godo\"\n)\n\nfunc main() {\n token := os.Getenv(\"DIGITALOCEAN_TOKEN\")\n\n client := godo.NewFromToken(token)\n ctx := context.TODO()\n\n key, _, err := client.Keys.GetByID(ctx, 512190)\n}"
- lang: Ruby
source: 'require ''droplet_kit''
token = ENV[''DIGITALOCEAN_TOKEN'']
client = DropletKit::Client.new(access_token: token)
client.ssh_keys.find(id: 512190) '
- lang: Python
source: 'import os
from pydo import Client
client = Client(token=os.environ.get("DIGITALOCEAN_TOKEN"))
resp = client.ssh_keys.get(ssh_key_identifier=512190)'
security:
- bearer_auth:
- ssh_key:read
put:
operationId: sshKeys_update
summary: Update an SSH Key's Name
description: To update the name of an SSH key, send a PUT request to either `/v2/account/keys/$SSH_KEY_ID` or `/v2/account/keys/$SSH_KEY_FINGERPRINT`. Set the `name` attribute to the new name you want to use.
tags:
- SSH Keys
parameters:
- $ref: '#/components/parameters/ssh_key_identifier'
requestBody:
description: Set the `name` attribute to the new name you want to use.
required: true
content:
application/json:
schema:
type: object
properties:
name:
$ref: '#/components/schemas/ssh_key_name'
responses:
'200':
$ref: '#/components/responses/sshKeys_existing'
'401':
$ref: '#/components/responses/unauthorized'
'404':
$ref: '#/components/responses/not_found'
'429':
$ref: '#/components/responses/too_many_requests'
'500':
$ref: '#/components/responses/server_error'
default:
$ref: '#/components/responses/unexpected_error'
x-codeSamples:
- lang: cURL
source: "curl -X PUT \\\n -H \"Content-Type: application/json\" \\\n -H \"Authorization: Bearer $DIGITALOCEAN_TOKEN\" \\\n -d '{\"name\":\"Renamed SSH Key\"}' \\\n \"https://api.digitalocean.com/v2/account/keys/512190\""
- lang: Go
source: "import (\n \"context\"\n \"os\"\n\n \"github.com/digitalocean/godo\"\n)\n\nfunc main() {\n token := os.Getenv(\"DIGITALOCEAN_TOKEN\")\n\n client := godo.NewFromToken(token)\n ctx := context.TODO()\n\n updateRequest := &godo.KeyUpdateRequest{\n Name: \"Renamed SSH Key\",\n }\n\n key, _, err := client.Keys.UpdateByID(ctx, 512190, updateRequest)\n}"
- lang: Ruby
source: 'require ''droplet_kit''
token = ENV[''DIGITALOCEAN_TOKEN'']
client = DropletKit::Client.new(access_token: token)
ssh_key = DropletKit::SSHKey.new(name: ''Renamed SSH Key'')
client.ssh_keys.update(ssh_key, id: 512190)'
- lang: Python
source: "import os\nfrom pydo import Client\n\nclient = Client(token=os.environ.get(\"DIGITALOCEAN_TOKEN\"))\n\nreq = {\n \"name\": \"My SSH Public Key\"\n}\n\nresp = client.ssh_keys.update(ssh_key_identifier=512190, body=req)"
security:
- bearer_auth:
- ssh_key:update
delete:
operationId: sshKeys_delete
summary: Delete an SSH Key
description: 'To destroy a public SSH key that you have in your account, send a DELETE request to `/v2/account/keys/$KEY_ID` or `/v2/account/keys/$KEY_FINGERPRINT`.
A 204 status will be returned, indicating that the action was successful and that the response body is empty.'
tags:
- SSH Keys
parameters:
- $ref: '#/components/parameters/ssh_key_identifier'
responses:
'204':
$ref: '#/components/responses/no_content'
'401':
$ref: '#/components/responses/unauthorized'
'404':
$ref: '#/components/responses/not_found'
'429':
$ref: '#/components/responses/too_many_requests'
'500':
$ref: '#/components/responses/server_error'
default:
$ref: '#/components/responses/unexpected_error'
x-codeSamples:
- lang: cURL
source: "curl -X DELETE \\\n -H \"Content-Type: application/json\" \\\n -H \"Authorization: Bearer $DIGITALOCEAN_TOKEN\" \\\n \"https://api.digitalocean.com/v2/account/keys/512190\" "
- lang: Go
source: "import (\n \"context\"\n \"os\"\n\n \"github.com/digitalocean/godo\"\n)\n\nfunc main() {\n token := os.Getenv(\"DIGITALOCEAN_TOKEN\")\n\n client := godo.NewFromToken(token)\n ctx := context.TODO()\n\n _, err := client.Keys.DeleteByID(ctx, 512190)\n}"
- lang: Ruby
source: 'require ''droplet_kit''
token = ENV[''DIGITALOCEAN_TOKEN'']
client = DropletKit::Client.new(access_token: token)
client.ssh_keys.delete(id: 512190)'
- lang: Python
source: 'import os
from pydo import Client
client = Client(token=os.environ.get("DIGITALOCEAN_TOKEN"))
resp = client.ssh_keys.delete(ssh_key_identifier=512190)'
security:
- bearer_auth:
- ssh_key:delete
components:
schemas:
meta_properties:
type: object
description: Information about the response itself.
properties:
total:
description: Number of objects returned by the request.
type: integer
example: 1
link_to_last_page:
type: object
properties:
last:
description: URI of the last page of the results.
type: string
example: https://api.digitalocean.com/v2/images?page=2
sshKeys:
type: object
properties:
id:
$ref: '#/components/schemas/ssh_key_id'
fingerprint:
$ref: '#/components/schemas/ssh_key_fingerprint'
public_key:
description: The entire public key string that was uploaded. Embedded into the root user's `authorized_keys` file if you include this key during Droplet creation.
type: string
example: ssh-rsa AEXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V example
name:
$ref: '#/components/schemas/ssh_key_name'
required:
- public_key
- name
ssh_key_name:
type: string
description: A human-readable display name for this key, used to easily identify the SSH keys when they are displayed.
example: My SSH Public Key
ssh_key_id:
type: integer
description: A unique identification number for this key. Can be used to embed a specific SSH key into a Droplet.
readOnly: true
example: 512189
error:
type: object
properties:
id:
description: A short identifier corresponding to the HTTP status code returned. For example, the ID for a response returning a 404 status code would be "not_found."
type: string
example: not_found
message:
description: A message providing additional information about the error, including details to help resolve it when possible.
type: string
example: The resource you were accessing could not be found.
request_id:
description: Optionally, some endpoints may include a request ID that should be provided when reporting bugs or opening support tickets to help identify the issue.
type: string
example: 4d9d8375-3c56-4925-a3e7-eb137fed17e9
required:
- id
- message
backward_links:
allOf:
- $ref: '#/components/schemas/link_to_first_page'
- $ref: '#/components/schemas/link_to_prev_page'
meta:
type: object
properties:
meta:
allOf:
- $ref: '#/components/schemas/meta_properties'
- required:
- total
required:
- meta
link_to_next_page:
type: object
properties:
next:
description: URI of the next page of the results.
type: string
example: https://api.digitalocean.com/v2/images?page=2
pagination:
type: object
properties:
links:
$ref: '#/components/schemas/page_links'
ssh_key_fingerprint:
type: string
description: A unique identifier that differentiates this key from other keys using a format that SSH recognizes. The fingerprint is created when the key is added to your account.
readOnly: true
example: 3b:16:bf:e4:8b:00:8b:b8:59:8c:a9:d3:f0:19:45:fa
link_to_prev_page:
type: object
properties:
prev:
description: URI of the previous page of the results.
type: string
example: https://api.digitalocean.com/v2/images?page=1
link_to_first_page:
type: object
properties:
first:
description: URI of the first page of the results.
type: string
example: https://api.digitalocean.com/v2/images?page=1
forward_links:
allOf:
- $ref: '#/components/schemas/link_to_last_page'
- $ref: '#/components/schemas/link_to_next_page'
page_links:
type: object
properties:
pages:
anyOf:
- $ref: '#/components/schemas/forward_links'
- $ref: '#/components/schemas/backward_links'
- {}
example:
pages:
first: https://api.digitalocean.com/v2/account/keys?page=1
prev: https://api.digitalocean.com/v2/account/keys?page=2
responses:
unexpected_error:
description: Unexpected error
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
$ref: '#/components/schemas/error'
example:
id: example_error
message: some error message
no_content:
description: The action was successful and the response body is empty.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
not_found:
description: The resource was not found.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
$ref: '#/components/schemas/error'
example:
id: not_found
message: The resource you requested could not be found.
sshKeys_all:
description: A JSON object with the key set to `ssh_keys`. The value is an array of `ssh_key` objects, each of which contains the standard `ssh_key` attributes.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
allOf:
- properties:
ssh_keys:
type: array
items:
$ref: '#/components/schemas/sshKeys'
- $ref: '#/components/schemas/pagination'
- $ref: '#/components/schemas/meta'
example:
ssh_keys:
- id: 289794
fingerprint: 3b:16:e4:bf:8b:00:8b:b8:59:8c:a9:d3:f0:19:fa:45
public_key: ssh-rsa ANOTHEREXAMPLEaC1yc2EAAAADAQABAAAAQQDDHr/jh2Jy4yALcK4JyWbVkPRaWmhck3IgCoeOO3z1e2dBowLh64QAM+Qb72pxekALga2oi4GvT+TlWNhzPH4V anotherexample
name: Other Public Key
links: {}
meta:
total: 1
too_many_requests:
description: API Rate limit exceeded
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
$ref: '#/components/schemas/error'
example:
id: too_many_requests
message: API Rate limit exceeded.
sshKeys_existing:
description: A JSON object with the key set to `ssh_key`. The value is an `ssh_key` object containing the standard `ssh_key` attributes.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
properties:
ssh_key:
$ref: '#/components/schemas/sshKeys'
links:
sshKeys_get_by_id:
$ref: '#/components/links/sshKeys_get_by_id'
sshKeys_get_by_fingerprint:
$ref: '#/components/links/sshKeys_get_by_fingerprint'
sshKeys_delete_by_id:
$ref: '#/components/links/sshKeys_delete_by_id'
sshKeys_delete_by_fingerprint:
$ref: '#/components/links/sshKeys_delete_by_fingerprint'
sshKeys_new:
description: The response body will be a JSON object with a key set to `ssh_key`.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
properties:
ssh_key:
$ref: '#/components/schemas/sshKeys'
links:
sshKeys_get_by_id:
$ref: '#/components/links/sshKeys_get_by_id'
sshKeys_get_by_fingerprint:
$ref: '#/components/links/sshKeys_get_by_fingerprint'
sshKeys_delete_by_id:
$ref: '#/components/links/sshKeys_delete_by_id'
sshKeys_delete_by_fingerprint:
$ref: '#/components/links/sshKeys_delete_by_fingerprint'
unauthorized:
description: Unauthorized
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
$ref: '#/components/schemas/error'
example:
id: unauthorized
message: Unable to authenticate you.
server_error:
description: Server error.
headers:
ratelimit-limit:
$ref: '#/components/headers/ratelimit-limit'
ratelimit-remaining:
$ref: '#/components/headers/ratelimit-remaining'
ratelimit-reset:
$ref: '#/components/headers/ratelimit-reset'
content:
application/json:
schema:
$ref: '#/components/schemas/error'
example:
id: server_error
message: Unexpected server-side error
parameters:
per_page:
in: query
name: per_page
required: false
description: Number of items returned per page
schema:
type: integer
minimum: 1
default: 20
maximum: 200
example: 2
ssh_key_identifier:
in: path
name: ssh_key_identifier
required: true
description: Either the ID or the fingerprint of an existing SSH key.
schema:
anyOf:
- $ref: '#/components/schemas/ssh_key_id'
- $ref: '#/components/schemas/ssh_key_fingerprint'
example: 512189
page:
in: query
name: page
required: false
description: Which 'page' of paginated results to return.
schema:
type: integer
minimum: 1
default: 1
example: 1
headers:
ratelimit-reset:
schema:
type: integer
example: 1444931833
description: The time when the oldest request will expire. The value is given in Unix epoch time. See https://developers.digitalocean.com/documentation/v2/#rate-limit for information about how requests expire.
ratelimit-remaining:
schema:
type: integer
example: 4816
description: The number of requests in your hourly quota that remain before you hit your request limit. See https://developers.digitalocean.com/documentation/v2/#rate-limit for information about how requests expire.
ratelimit-limit:
schema:
type: integer
example: 5000
description: The default limit on number of requests that can be made per hour and per minute. Current rate limits are 5000 requests per hour and 250 requests per minute.
links:
sshKeys_delete_by_fingerprint:
operationId: ssh_keys_delete_by_fingerprint
parameters:
ssh_key_identifier: $response.body#/ssh_key/fingerprint
description: The `fingerprint` value returned in the response can be used as the `ssh_key_identifier` parameter in `DELETE /v2/account/keys/{ssh_key_identifier}`.
sshKeys_get_by_id:
operationId: sshKeys_get_by_id
parameters:
ssh_key_identifier: $response.body#/ssh_key/id
description: The `id` value returned in the response can be used as the `ssh_key_identifier` parameter in `GET /v2/account/keys/{ssh_key_identifier}`.
sshKeys_delete_by_id:
operationId: sshKeys_delete_by_id
parameters:
ssh_key_identifier: $response.body#/ssh_key/id
description: The `id` value returned in the response can be used as the `ssh_key_identifier` parameter in `DELETE /v2/account/keys/{ssh_key_identifier}`.
sshKeys_get_by_fingerprint:
operationId: sshKeys_get_by_fingerprint
parameters:
ssh_key_identifier: $response.body#/ssh_key/fingerprint
description: The `fingerprint` value returned in the response can be used as the `ssh_key_identifier` parameter in `GET /v2/account/keys/{ssh_key_identifier}`.
securitySchemes:
bearer_auth:
type: http
scheme: bearer
description: '## OAuth Authentication
In order to interact with the DigitalOcean API, you or your application must
authenticate.
The DigitalOcean API handles this through OAuth, an open standard for
authorization. OAuth allows you to delegate access to your account.
Scopes can be used to grant full access, read-only access, or access to
a specific set of endpoints.
You can generate an OAuth token by visiting the [Apps & API](https://cloud.digitalocean.com/account/api/tokens)
section of the DigitalOcean control panel for your account.
An OAuth token functions as a complete authentication request. In effect, it
acts as a substitute for a username and password pair.
Because of this, it is absolutely **essential** that you keep your OAuth
tokens secure. In fact, upon generation, the web interface will only display
each token a single time in order to prevent the token from being compromised.
DigitalOcean access tokens begin with an identifiable prefix in order to
distinguish them from other similar tokens.
- `dop_v1_` for personal access tokens generated in the control panel
- `doo_v1_` for tokens generated by applications using [the OAuth flow](https://docs.digitalocean.com/reference/api/oauth-api/)
- `dor_v1_` for OAuth refresh tokens
### Scopes
Scopes act like permissions assigned to an API token. These permissions
determine what actions the token can perform. You can create API
tokens that grant read-only access, full access, or limited access to
specific endpoints by using custom scopes.
Generally, scopes are designed to match HTTP verbs and common CRUD
operations (Create, Read, Update, Delete).
| HTTP Verb | CRUD Operation | Scope |
|---|---|---|
| GET | Read | `<resource>:read` |
| POST | Create | `<resource>:create` |
| PUT/PATCH | Update | `<resource>:update` |
| DELETE | Delete | `<resource>:delete` |
For example, creating a new Droplet by making a `POST` request to the
`/v2/droplets` endpoint requires the `droplet:create` scope while
listing Droplets by making a `GET` request to the `/v2/droplets`
endpoint requires the `droplet:read` scope.
Each endpoint below specifies which scope is required to access it when
using custom scopes.
### How to Authenticate with OAuth
In order to make an authenticated request, include a bearer-type
`Authorization` header containing your OAuth token. All requests must be
made over HTTPS.
### Authenticate with a Bearer Authorization Header
```
curl -X $HTTP_METHOD -H "Authorization: Bearer $DIGITALOCEAN_TOKEN" "https://api.digitalocean.com/v2/$OBJECT"
```
'