Posit Service Tokens API

The Service Tokens API from Posit — 3 operation(s) for service tokens.

Operations 4

GET /v1/system/service-tokens List service tokens #
POST /v1/system/service-tokens Create a service token #
GET /v1/system/service-tokens/scopes List available scopes #
DELETE /v1/system/service-tokens/{guid} Delete a service token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/posit-service-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

posit-service-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: support@posit.co
    name: Posit Connect Support
    url: https://support.posit.co/hc/en-us
  description: '## Overview


    The Posit Connect Server API can be used to perform certain

    user actions remotely.'
  license:
    name: Commercial. Copyright 2015-2026 Posit Software, PBC. All Rights Reserved.
    url: https://posit.co/about/eula/
  termsOfService: https://posit.co/about/eula/
  title: Posit Connect API Reference Service Tokens API
  version: 1.0.1
servers:
- url: /__api__
security:
- apiKey: []
tags:
- name: Service Tokens
paths:
  /v1/system/service-tokens:
    get:
      description: 'List all service tokens.

        This endpoint is available only to administrators.'
      operationId: listServiceTokens
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/ServiceToken'
                type: array
          description: Successful response.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: List service tokens
      tags:
      - Service Tokens
    post:
      description: 'Create a new service token with the specified scopes.

        This response includes the full token key. **Subsequent requests

        do not include the key value.**

        This endpoint is available only to administrators.'
      operationId: createServiceToken
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceTokenCreateInput'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceToken'
          description: Successful response.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation is invalid.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: Create a service token
      tags:
      - Service Tokens
  /v1/system/service-tokens/scopes:
    get:
      description: 'List all available scopes you can assign to service tokens.

        This endpoint is available only to administrators.'
      operationId: listServiceTokenScopes
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceTokenScopes'
          description: Successful response.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: List available scopes
      tags:
      - Service Tokens
  /v1/system/service-tokens/{guid}:
    delete:
      description: 'Delete a service token. The token will immediately stop working for

        authentication.

        This endpoint is available only to administrators.'
      operationId: deleteServiceToken
      parameters:
      - in: path
        name: guid
        required: true
        schema:
          format: uuid
          type: string
      responses:
        '204':
          description: Successful response.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation is invalid.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested operation requires authentication.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: You do not have permission to perform this operation.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: The requested object does not exist.
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIError'
          description: A server error occurred.
      summary: Delete a service token
      tags:
      - Service Tokens
components:
  schemas:
    APIError:
      additionalProperties: false
      description: The error object returned by the API on failure.
      properties:
        code:
          description: The specific code for the type of error returned. See the [API error codes reference](#api-error-codes) for the full set of values.
          type: integer
        error:
          description: A description of the problem that was encountered.
          type: string
        payload:
          description: Additional error details, if any. The structure varies by error type.
          type:
          - object
          - 'null'
      required:
      - code
      - error
      type: object
    ServiceTokenScopes:
      additionalProperties: false
      description: An object containing the available scopes for service tokens.
      properties:
        scopes:
          description: The available scopes.
          items:
            $ref: '#/components/schemas/ServiceTokenScope'
          type: array
      type: object
    ServiceTokenScope:
      additionalProperties: false
      description: A scope you can assign to a service token.
      properties:
        name:
          description: The scope identifier.
          example: nameservice:read
          type: string
        description:
          description: A human-readable description of what this scope grants.
          example: Access NSS user and group data
          type: string
      type: object
    ServiceTokenCreateInput:
      additionalProperties: false
      description: The input object for creating a service token.
      properties:
        name:
          description: 'The name for this service token. Use the name to describe the purpose

            of the token. Names do not need to be unique.'
          example: NSS Integration
          type: string
        scopes:
          description: 'The scopes to grant to this service token. At least one scope is

            required. Supported values: `identity:manage`, `nameservice:read`.

            Use the `/v1/system/service-tokens/scopes` endpoint to get available scopes

            and descriptions.'
          example:
          - identity:manage
          items:
            type: string
          type: array
        expires_at:
          description: 'Optional timestamp (in [RFC 3339](https://www.rfc-editor.org/rfc/rfc3339)

            format) indicating when the token expires. After this time, the token

            can no longer authenticate and is removed automatically. Must be in

            the future. Omit or set to `null` for a token that never expires.'
          example: '2026-12-31T00:00:00Z'
          format: date-time
          type:
          - string
          - 'null'
      type: object
    ServiceToken:
      additionalProperties: false
      description: Object containing service token details.
      properties:
        guid:
          description: The unique identifier for this service token.
          example: f2aba5e9-1c6a-4f63-91c7-ec6ea5a2f8e7
          format: uuid
          type: string
        name:
          description: 'The name for this service token. The name often describes the purpose

            of the token.'
          example: NSS Integration
          type: string
        key:
          description: 'The secret key for this service token. The full key appears only

            when you create the token. **Subsequent reads do not include the key.**'
          example: abcdefghijklmnopqrstuvwxyz123456
          type: string
        scopes:
          description: 'The scopes granted to this service token. Supported values:

            `identity:manage`, `nameservice:read`.'
          example:
          - identity:manage
          items:
            type: string
          type: array
        created_time:
          description: 'Timestamp (in [RFC 3339](https://www.rfc-editor.org/rfc/rfc3339)

            format) indicating when you created the token.'
          example: '2006-01-02T15:04:05-07:00'
          format: date-time
          type: string
        active_time:
          description: 'Timestamp (in [RFC 3339](https://www.rfc-editor.org/rfc/rfc3339)

            format) indicating approximately when the token last authenticated.

            This value is updated when the token is used, but no more than once

            every 15 minutes.'
          example: '2006-01-02T15:04:05-07:00'
          format: date-time
          type: string
        expires_at:
          description: 'Timestamp (in [RFC 3339](https://www.rfc-editor.org/rfc/rfc3339)

            format) indicating when the token expires, or `null` if the token never

            expires.'
          example: '2026-12-31T00:00:00Z'
          format: date-time
          type:
          - string
          - 'null'
      type: object
  securitySchemes:
    apiKey:
      description: 'Prefix your API key with `Key `, e.g. `Key ABC123`.

        '
      in: header
      name: Authorization
      type: apiKey