Docker Hub Org Access Tokens API
The organization access token endpoints allow you to manage organization access tokens (OATs). See [Organization access tokens](https://docs.docker.com/security/for-admins/access-tokens/) for more information.
The organization access token endpoints allow you to manage organization access tokens (OATs). See [Organization access tokens](https://docs.docker.com/security/for-admins/access-tokens/) for more information.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/docker-hub-org-access-tokens-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Docker HUB Org Access Tokens API
version: 2-beta
x-logo:
url: https://docs.docker.com/assets/images/logo-docker-main.png
href: /reference
description: 'Docker Hub is a service provided by Docker for finding and sharing container images with your team.
It is the world''s largest library and community for container images.
In addition to the Docker Hub UI and Docker Hub CLI tool (currently experimental), Docker provides an API that allows you to interact with Docker Hub.
Browse through the Docker Hub API documentation to explore the supported endpoints.'
servers:
- description: Docker HUB API
x-audience: public
url: https://hub.docker.com
tags:
- name: org-access-tokens
x-displayName: Organization Access Tokens
x-audience: public
description: The organization access token endpoints allow you to manage organization access tokens (OATs). See Organization access tokens for more information.
paths:
/v2/orgs/{name}/access-tokens:
post:
summary: Create access token
description: Create an access token for an organization.
tags:
- org-access-tokens
security:
- bearerAuth: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/createOrgAccessTokenRequest'
required: true
responses:
'201':
description: Created
content:
application/json:
schema:
$ref: '#/components/schemas/createOrgAccessTokenResponse'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
operationId: postV2OrgsByNameAccessTokens
x-operation-id-source: derived
get:
summary: List access tokens
description: List access tokens for an organization.
tags:
- org-access-tokens
security:
- bearerAuth: []
parameters:
- in: query
name: page
schema:
type: number
default: 1
- in: query
name: page_size
schema:
type: number
default: 10
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/getOrgAccessTokensResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
operationId: getV2OrgsByNameAccessTokens
x-operation-id-source: derived
/v2/orgs/{org_name}/access-tokens/{access_token_id}:
parameters:
- $ref: '#/components/parameters/org_name'
- in: path
name: access_token_id
required: true
schema:
type: string
description: The ID of the access token to retrieve
example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
get:
summary: Get access token
description: Get details of a specific access token for an organization.
tags:
- org-access-tokens
security:
- bearerAuth: []
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/getOrgAccessTokenResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
operationId: getV2OrgsByOrgNameAccessTokensByAccessTokenId
x-operation-id-source: derived
patch:
summary: Update access token
description: Update a specific access token for an organization.
tags:
- org-access-tokens
security:
- bearerAuth: []
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/updateOrgAccessTokenRequest'
required: true
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/updateOrgAccessTokenResponse'
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
operationId: patchV2OrgsByOrgNameAccessTokensByAccessTokenId
x-operation-id-source: derived
delete:
summary: Delete access token
description: Delete a specific access token for an organization. This action cannot be undone.
tags:
- org-access-tokens
security:
- bearerAuth: []
responses:
'204':
description: Access token deleted successfully
'401':
$ref: '#/components/responses/Unauthorized'
'403':
$ref: '#/components/responses/Forbidden'
'404':
$ref: '#/components/responses/NotFound'
operationId: deleteV2OrgsByOrgNameAccessTokensByAccessTokenId
x-operation-id-source: derived
components:
responses:
Forbidden:
description: Forbidden
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
BadRequest:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/ValueError'
NotFound:
description: Not Found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
schemas:
createOrgAccessTokenResponse:
type: object
allOf:
- type: object
properties:
id:
type: string
example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
label:
type: string
example: My organization token
is_active:
type: boolean
example: true
created_at:
type: string
format: date-time
example: '2022-05-20T00:54:18Z'
expires_at:
type:
- string
- 'null'
format: date-time
example: '2023-05-20T00:54:18Z'
last_used_at:
type:
- string
- 'null'
format: date-time
example: '2022-06-15T12:30:45Z'
- type: object
properties:
token:
type: string
description: The actual token value that can be used for authentication
example: dckr_oat_7awgM4jG5SQvxcvmNzhKj8PQjxo
resources:
type: array
items:
$ref: '#/components/schemas/orgAccessTokenResource'
ValueError:
type: object
description: Used to error if input validation fails.
properties:
fields:
type: object
items:
type: string
text:
type: string
getOrgAccessTokenResponse:
allOf:
- $ref: '#/components/schemas/orgAccessToken'
- type: object
properties:
resources:
type: array
description: Resources this token has access to
items:
$ref: '#/components/schemas/orgAccessTokenResource'
updateOrgAccessTokenResponse:
type: object
allOf:
- $ref: '#/components/schemas/orgAccessToken'
- type: object
properties:
resources:
type: array
description: Resources this token has access to
items:
$ref: '#/components/schemas/orgAccessTokenResource'
createOrgAccessTokenRequest:
type: object
properties:
label:
type: string
description: Label for the access token
example: My organization token
required: true
description:
type: string
description: Description of the access token
example: Token for CI/CD pipeline
resources:
type: array
description: Resources this token has access to
items:
$ref: '#/components/schemas/orgAccessTokenResource'
expires_at:
type:
- string
- 'null'
format: date-time
description: Expiration date for the token
example: '2023-05-20T00:54:18Z'
orgAccessTokenResource:
type: object
properties:
type:
type: string
enum:
- TYPE_REPO
- TYPE_ORG
example: TYPE_REPO
description: The type of resource
required: true
path:
type: string
example: myorg/myrepo
description: 'The path of the resource. The format of this will change depending on the type of resource.
For TYPE_REPO resources:
- Must be an existing repository name (e.g., "myorg/myrepo")
- Can use glob patterns (e.g., "myorg/*" for all repositories in the organization)
- Use "*/*/public" to reference all public repositories
'
required: true
scopes:
type: array
description: The scopes this token has access to
items:
type: string
example: scope-image-pull
required: true
updateOrgAccessTokenRequest:
type: object
properties:
label:
type: string
description: Label for the access token
example: My organization token
description:
type: string
description: Description of the access token
example: Token for CI/CD pipeline
resources:
type: array
description: Resources this token has access to
items:
$ref: '#/components/schemas/orgAccessTokenResource'
is_active:
type: boolean
description: Whether the token is active
example: true
Error:
type: object
properties:
detail:
type: string
message:
type: string
orgAccessToken:
type: object
properties:
id:
type: string
example: a7a5ef25-8889-43a0-8cc7-f2a94268e861
label:
type: string
example: My organization token
created_by:
type: string
example: johndoe
is_active:
type: boolean
example: true
created_at:
type: string
format: date-time
example: '2022-05-20T00:54:18Z'
expires_at:
type:
- string
- 'null'
format: date-time
example: '2023-05-20T00:54:18Z'
last_used_at:
type:
- string
- 'null'
format: date-time
example: '2022-06-15T12:30:45Z'
getOrgAccessTokensResponse:
type: object
properties:
total:
type: number
example: 10
next:
type: string
example: https://hub.docker.com/v2/orgs/docker/access-tokens?page=2&page_size=10
previous:
type: string
example: https://hub.docker.com/v2/orgs/docker/access-tokens?page=1&page_size=10
results:
type: array
items:
$ref: '#/components/schemas/orgAccessToken'
parameters:
org_name:
in: path
name: org_name
description: Name of the organization (namespace).
schema:
type: string
example: myorganization
required: true
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
bearerSCIMAuth:
type: http
scheme: bearer
x-tagGroups:
- name: General
tags:
- changelog
- resources
- rate-limiting
- authentication
- name: API
tags:
- authentication-api
- access-tokens
- images
- audit-logs
- org-settings
- repositories
- scim
- orgs
- org-access-tokens
- groups
- invites