Docker Hub Access Tokens API

The Personal Access Token endpoints lets you manage personal access tokens. For more information, see [Access Tokens](https://docs.docker.com/security/access-tokens/). You can use a personal access token instead of a password in the [Docker CLI](https://docs.docker.com/engine/reference/commandline/cli/) or in the [Create an authentication token](#operation/PostUsersLogin) route to obtain a bearer token. ### Scopes For each scope grouping (in this case "repo"), you only need to define 1 scope as any lower scopes are assumed. For example: If you define `repo:write`, the API assumes the scope of both `repo:read` *and* `repo:public_read` as well. If you were to define both `repo:write` *and* `repo:read`, then `repo:read` is assumed by `repo:write` and ignored. ***Treat your personal access token like your password and keep it secret. You cannot retrieve your token after it is generated.***

Operations 5

POST /v2/access-tokens Create personal access token #
GET /v2/access-tokens List personal access tokens #
PATCH /v2/access-tokens/{uuid} Update personal access token #
GET /v2/access-tokens/{uuid} Get personal access token #
DELETE /v2/access-tokens/{uuid} Delete personal access token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/docker-hub-access-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

docker-hub-access-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Docker HUB Access Tokens API
  version: 2-beta
  x-logo:
    url: https://docs.docker.com/assets/images/logo-docker-main.png
    href: /reference
  description: 'Docker Hub is a service provided by Docker for finding and sharing container images with your team.


    It is the world''s largest library and community for container images.


    In addition to the Docker Hub UI and Docker Hub CLI tool (currently experimental), Docker provides an API that allows you to interact with Docker Hub.


    Browse through the Docker Hub API documentation to explore the supported endpoints.'
servers:
- description: Docker HUB API
  x-audience: public
  url: https://hub.docker.com
tags:
- name: Access Tokens
  x-displayName: Personal Access Tokens
  description: The Personal Access Token endpoints lets you manage personal access tokens.
paths:
  /v2/access-tokens:
    post:
      summary: Create personal access token
      description: Creates and returns a personal access token.
      tags:
      - Access Tokens
      security:
      - bearerAuth: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/createAccessTokenRequest'
        required: true
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/createAccessTokensResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      operationId: postV2AccessTokens
      x-operation-id-source: derived
    get:
      summary: List personal access tokens
      description: Returns a paginated list of personal access tokens.
      tags:
      - Access Tokens
      security:
      - bearerAuth: []
      parameters:
      - in: query
        name: page
        schema:
          type: number
          default: 1
      - in: query
        name: page_size
        schema:
          type: number
          default: 10
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/getAccessTokensResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      operationId: getV2AccessTokens
      x-operation-id-source: derived
  /v2/access-tokens/{uuid}:
    parameters:
    - in: path
      name: uuid
      required: true
      schema:
        type: string
    patch:
      summary: Update personal access token
      description: Updates a personal access token partially. You can either update the token's label or enable/disable it.
      tags:
      - Access Tokens
      security:
      - bearerAuth: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/patchAccessTokenRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/patchAccessTokenResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      operationId: patchV2AccessTokensByUuid
      x-operation-id-source: derived
    get:
      summary: Get personal access token
      description: Returns a personal access token by UUID.
      tags:
      - Access Tokens
      security:
      - bearerAuth: []
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/accessToken'
                - type: object
                  properties:
                    token:
                      type: string
                      example: ''
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: getV2AccessTokensByUuid
      x-operation-id-source: derived
    delete:
      summary: Delete personal access token
      description: Deletes a personal access token permanently. This cannot be undone.
      tags:
      - Access Tokens
      security:
      - bearerAuth: []
      responses:
        '204':
          description: A successful response.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: deleteV2AccessTokensByUuid
      x-operation-id-source: derived
components:
  schemas:
    patchAccessTokenRequest:
      type: object
      properties:
        token_label:
          type: string
          example: My read only token
          minLength: 1
          maxLength: 100
        is_active:
          type: boolean
          example: false
    ValueError:
      type: object
      description: Used to error if input validation fails.
      properties:
        fields:
          type: object
          items:
            type: string
        text:
          type: string
    createAccessTokenRequest:
      type: object
      required:
      - token_label
      - scopes
      properties:
        token_label:
          type: string
          description: Friendly name for you to identify the token.
          example: My read only token
          minLength: 1
          maxLength: 100
        scopes:
          type: array
          description: 'Valid scopes: "repo:admin", "repo:write", "repo:read", "repo:public_read"

            '
          example:
          - repo:read
          items:
            type: string
        expires_at:
          type: string
          description: 'Optional expiration date for the token.

            If omitted, the token will remain valid indefinitely.

            '
          format: date-time
          example: '2021-10-28T18:30:19.520861Z'
    patchAccessTokenResponse:
      $ref: '#/components/schemas/accessToken'
    getAccessTokensResponse:
      type: object
      properties:
        count:
          type: number
          example: 1
        next:
          type: string
          example: null
        previous:
          type: string
          example: null
        active_count:
          type: number
          example: 1
        results:
          type: array
          items:
            allOf:
            - $ref: '#/components/schemas/accessToken'
            - type: object
              properties:
                token:
                  type: string
                  example: ''
    Error:
      type: object
      properties:
        detail:
          type: string
        message:
          type: string
    createAccessTokensResponse:
      $ref: '#/components/schemas/accessToken'
    accessToken:
      type: object
      properties:
        uuid:
          type: string
          example: b30bbf97-506c-4ecd-aabc-842f3cb484fb
        client_id:
          type: string
          example: HUB
        creator_ip:
          type: string
          example: 127.0.0.1
        creator_ua:
          type: string
          example: some user agent
        created_at:
          type: string
          example: '2021-07-20T12:00:00.000000Z'
        last_used:
          type:
          - string
          - 'null'
          example: null
        generated_by:
          type: string
          example: manual
        is_active:
          type: boolean
          example: true
        token:
          type: string
          example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
        token_label:
          type: string
          example: My read only token
        scopes:
          type: array
          example:
          - repo:read
          items:
            type: string
        expires_at:
          type: string
          format: date-time
          example: '2021-10-28T18:30:19.520861Z'
  responses:
    BadRequest:
      description: Bad Request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ValueError'
    NotFound:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    bearerSCIMAuth:
      type: http
      scheme: bearer
x-tagGroups:
- name: General
  tags:
  - changelog
  - resources
  - rate-limiting
  - authentication
- name: API
  tags:
  - authentication-api
  - access-tokens
  - images
  - audit-logs
  - org-settings
  - repositories
  - scim
  - orgs
  - org-access-tokens
  - groups
  - invites