Docker Hub Org Access Tokens API

The organization access token endpoints allow you to manage organization access tokens (OATs). See [Organization access tokens](https://docs.docker.com/security/for-admins/access-tokens/) for more information.

Operations 5

POST /v2/orgs/{name}/access-tokens Create access token #
GET /v2/orgs/{name}/access-tokens List access tokens #
GET /v2/orgs/{org_name}/access-tokens/{access_token_id} Get access token #
PATCH /v2/orgs/{org_name}/access-tokens/{access_token_id} Update access token #
DELETE /v2/orgs/{org_name}/access-tokens/{access_token_id} Delete access token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/docker-hub-org-access-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

docker-hub-org-access-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Docker HUB Org Access Tokens API
  version: 2-beta
  x-logo:
    url: https://docs.docker.com/assets/images/logo-docker-main.png
    href: /reference
  description: 'Docker Hub is a service provided by Docker for finding and sharing container images with your team.


    It is the world''s largest library and community for container images.


    In addition to the Docker Hub UI and Docker Hub CLI tool (currently experimental), Docker provides an API that allows you to interact with Docker Hub.


    Browse through the Docker Hub API documentation to explore the supported endpoints.'
servers:
- description: Docker HUB API
  x-audience: public
  url: https://hub.docker.com
tags:
- name: org-access-tokens
  x-displayName: Organization Access Tokens
  x-audience: public
  description: The organization access token endpoints allow you to manage organization access tokens (OATs). See Organization access tokens for more information.
paths:
  /v2/orgs/{name}/access-tokens:
    post:
      summary: Create access token
      description: Create an access token for an organization.
      tags:
      - org-access-tokens
      security:
      - bearerAuth: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/createOrgAccessTokenRequest'
        required: true
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/createOrgAccessTokenResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: postV2OrgsByNameAccessTokens
      x-operation-id-source: derived
    get:
      summary: List access tokens
      description: List access tokens for an organization.
      tags:
      - org-access-tokens
      security:
      - bearerAuth: []
      parameters:
      - in: query
        name: page
        schema:
          type: number
          default: 1
      - in: query
        name: page_size
        schema:
          type: number
          default: 10
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/getOrgAccessTokensResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: getV2OrgsByNameAccessTokens
      x-operation-id-source: derived
  /v2/orgs/{org_name}/access-tokens/{access_token_id}:
    parameters:
    - $ref: '#/components/parameters/org_name'
    - in: path
      name: access_token_id
      required: true
      schema:
        type: string
      description: The ID of the access token to retrieve
      example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
    get:
      summary: Get access token
      description: Get details of a specific access token for an organization.
      tags:
      - org-access-tokens
      security:
      - bearerAuth: []
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/getOrgAccessTokenResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: getV2OrgsByOrgNameAccessTokensByAccessTokenId
      x-operation-id-source: derived
    patch:
      summary: Update access token
      description: Update a specific access token for an organization.
      tags:
      - org-access-tokens
      security:
      - bearerAuth: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/updateOrgAccessTokenRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/updateOrgAccessTokenResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: patchV2OrgsByOrgNameAccessTokensByAccessTokenId
      x-operation-id-source: derived
    delete:
      summary: Delete access token
      description: Delete a specific access token for an organization. This action cannot be undone.
      tags:
      - org-access-tokens
      security:
      - bearerAuth: []
      responses:
        '204':
          description: Access token deleted successfully
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      operationId: deleteV2OrgsByOrgNameAccessTokensByAccessTokenId
      x-operation-id-source: derived
components:
  responses:
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: Bad Request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ValueError'
    NotFound:
      description: Not Found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    createOrgAccessTokenResponse:
      type: object
      allOf:
      - type: object
        properties:
          id:
            type: string
            example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
          label:
            type: string
            example: My organization token
          is_active:
            type: boolean
            example: true
          created_at:
            type: string
            format: date-time
            example: '2022-05-20T00:54:18Z'
          expires_at:
            type:
            - string
            - 'null'
            format: date-time
            example: '2023-05-20T00:54:18Z'
          last_used_at:
            type:
            - string
            - 'null'
            format: date-time
            example: '2022-06-15T12:30:45Z'
      - type: object
        properties:
          token:
            type: string
            description: The actual token value that can be used for authentication
            example: dckr_oat_7awgM4jG5SQvxcvmNzhKj8PQjxo
          resources:
            type: array
            items:
              $ref: '#/components/schemas/orgAccessTokenResource'
    ValueError:
      type: object
      description: Used to error if input validation fails.
      properties:
        fields:
          type: object
          items:
            type: string
        text:
          type: string
    getOrgAccessTokenResponse:
      allOf:
      - $ref: '#/components/schemas/orgAccessToken'
      - type: object
        properties:
          resources:
            type: array
            description: Resources this token has access to
            items:
              $ref: '#/components/schemas/orgAccessTokenResource'
    updateOrgAccessTokenResponse:
      type: object
      allOf:
      - $ref: '#/components/schemas/orgAccessToken'
      - type: object
        properties:
          resources:
            type: array
            description: Resources this token has access to
            items:
              $ref: '#/components/schemas/orgAccessTokenResource'
    createOrgAccessTokenRequest:
      type: object
      properties:
        label:
          type: string
          description: Label for the access token
          example: My organization token
          required: true
        description:
          type: string
          description: Description of the access token
          example: Token for CI/CD pipeline
        resources:
          type: array
          description: Resources this token has access to
          items:
            $ref: '#/components/schemas/orgAccessTokenResource'
        expires_at:
          type:
          - string
          - 'null'
          format: date-time
          description: Expiration date for the token
          example: '2023-05-20T00:54:18Z'
    orgAccessTokenResource:
      type: object
      properties:
        type:
          type: string
          enum:
          - TYPE_REPO
          - TYPE_ORG
          example: TYPE_REPO
          description: The type of resource
          required: true
        path:
          type: string
          example: myorg/myrepo
          description: 'The path of the resource. The format of this will change depending on the type of resource.


            For TYPE_REPO resources:

            - Must be an existing repository name (e.g., "myorg/myrepo")

            - Can use glob patterns (e.g., "myorg/*" for all repositories in the organization)

            - Use "*/*/public" to reference all public repositories

            '
          required: true
        scopes:
          type: array
          description: The scopes this token has access to
          items:
            type: string
            example: scope-image-pull
          required: true
    updateOrgAccessTokenRequest:
      type: object
      properties:
        label:
          type: string
          description: Label for the access token
          example: My organization token
        description:
          type: string
          description: Description of the access token
          example: Token for CI/CD pipeline
        resources:
          type: array
          description: Resources this token has access to
          items:
            $ref: '#/components/schemas/orgAccessTokenResource'
        is_active:
          type: boolean
          description: Whether the token is active
          example: true
    Error:
      type: object
      properties:
        detail:
          type: string
        message:
          type: string
    orgAccessToken:
      type: object
      properties:
        id:
          type: string
          example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
        label:
          type: string
          example: My organization token
        created_by:
          type: string
          example: johndoe
        is_active:
          type: boolean
          example: true
        created_at:
          type: string
          format: date-time
          example: '2022-05-20T00:54:18Z'
        expires_at:
          type:
          - string
          - 'null'
          format: date-time
          example: '2023-05-20T00:54:18Z'
        last_used_at:
          type:
          - string
          - 'null'
          format: date-time
          example: '2022-06-15T12:30:45Z'
    getOrgAccessTokensResponse:
      type: object
      properties:
        total:
          type: number
          example: 10
        next:
          type: string
          example: https://hub.docker.com/v2/orgs/docker/access-tokens?page=2&page_size=10
        previous:
          type: string
          example: https://hub.docker.com/v2/orgs/docker/access-tokens?page=1&page_size=10
        results:
          type: array
          items:
            $ref: '#/components/schemas/orgAccessToken'
  parameters:
    org_name:
      in: path
      name: org_name
      description: Name of the organization (namespace).
      schema:
        type: string
      example: myorganization
      required: true
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    bearerSCIMAuth:
      type: http
      scheme: bearer
x-tagGroups:
- name: General
  tags:
  - changelog
  - resources
  - rate-limiting
  - authentication
- name: API
  tags:
  - authentication-api
  - access-tokens
  - images
  - audit-logs
  - org-settings
  - repositories
  - scim
  - orgs
  - org-access-tokens
  - groups
  - invites