Saperly API Token Registry API

Manage the scoped `sk_` API keys agents use to call Saperly. Each key carries a set of scopes, an optional number allow-list, and an optional spend cap; revoke a key when it is no longer needed.

Operations 2

POST /workspaces/{slug}/api-tokens Create a scoped API token #
POST /workspaces/{slug}/api-tokens/{tokenId}/revoke Revoke an API token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/saperly:saperly-api-token-registry-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

saperly-api-token-registry-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Saperly API Token Registry API
  version: 0.1.0
  description: 'Operations tagged api-token-registry across 2 of this provider''s published API definitions: api-saperly-com-openapi.json, saperly-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: /
  description: This worker
- url: https://api.saperly.com
  description: Production
security: []
tags:
- name: api-token-registry
  description: Manage the scoped `sk_` API keys agents use to call Saperly. Each key carries a set of scopes, an optional number allow-list, and an optional spend cap; revoke a key when it is no longer needed.
paths:
  /workspaces/{slug}/api-tokens:
    post:
      tags:
      - api-token-registry
      operationId: api-token-registry.create
      parameters:
      - name: slug
        in: path
        schema:
          type: string
          description: The workspace's URL slug.
        required: true
      security: []
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  name:
                    type: string
                  prefix:
                    type: string
                  scopes:
                    type: array
                    items:
                      type: string
                      enum:
                      - read
                      - write
                      - admin
                  lastUsedAt:
                    anyOf:
                    - type: string
                    - type: 'null'
                  createdAt:
                    type: string
                  token:
                    type: string
                required:
                - id
                - name
                - prefix
                - scopes
                - lastUsedAt
                - createdAt
                - token
                additionalProperties: false
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Unauthorized'
        '403':
          description: AuthorizationDenied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationDenied'
        '404':
          description: WorkspaceNotFound
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WorkspaceNotFound'
        '429':
          description: RateLimited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RateLimited'
        '500':
          description: InternalError
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalError'
      summary: Create a scoped API token
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  allOf:
                  - minLength: 1
                  - maxLength: 100
                scopes:
                  type: array
                  items:
                    type: string
                    enum:
                    - read
                    - write
                    - admin
                  allOf:
                  - minItems: 1
                  - maxItems: 3
                numberScope:
                  anyOf:
                  - type: array
                    items:
                      type: string
                  - type: 'null'
                spendLimitCents:
                  anyOf:
                  - type: number
                    allOf:
                    - minimum: 1
                  - type: 'null'
                spendLimitResetPeriod:
                  anyOf:
                  - anyOf:
                    - type: string
                      enum:
                      - monthly
                    - type: 'null'
                  - type: 'null'
              required:
              - name
              - scopes
              additionalProperties: false
              description: 'The new token: a display `name`, the `scopes` it may exercise, an optional `numberScope` allow-list of phone-number ids, and an optional per-key `spendLimitCents` cap (with `spendLimitResetPeriod`). The full secret is returned once on create.'
        required: true
    servers:
    - url: /
      description: This worker
  /workspaces/{slug}/api-tokens/{tokenId}/revoke:
    post:
      tags:
      - api-token-registry
      operationId: api-token-registry.revoke
      parameters:
      - name: slug
        in: path
        schema:
          type: string
          description: The URL-safe slug identifying the workspace.
        required: true
      - name: tokenId
        in: path
        schema:
          type: string
          description: The id of the API token to revoke.
        required: true
      security: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: string
                    enum:
                    - revoked
                required:
                - status
                additionalProperties: false
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Unauthorized'
        '403':
          description: AuthorizationDenied
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationDenied'
        '404':
          description: WorkspaceNotFound
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WorkspaceNotFound'
        '429':
          description: RateLimited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RateLimited'
        '500':
          description: InternalError
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InternalError'
      summary: Revoke an API token
    servers:
    - url: /
      description: This worker
components:
  schemas:
    RateLimited:
      type: object
      properties:
        _tag:
          type: string
          enum:
          - RateLimited
        bucket:
          type: string
          description: The rate-limit bucket that was exhausted.
      required:
      - _tag
      - bucket
      additionalProperties: false
    Unauthorized:
      type: object
      properties:
        _tag:
          type: string
          enum:
          - Unauthorized
        message:
          type: string
          description: Why the request was rejected (missing, invalid, or insufficient credentials).
      required:
      - _tag
      - message
      additionalProperties: false
    WorkspaceNotFound:
      type: object
      properties:
        _tag:
          type: string
          enum:
          - WorkspaceNotFound
        slug:
          type: string
      required:
      - _tag
      - slug
      additionalProperties: false
    InternalError:
      type: object
      properties:
        _tag:
          type: string
          enum:
          - InternalError
        traceId:
          type: string
          description: A correlation id for this failure — quote it when reporting the problem so the request can be traced.
      required:
      - _tag
      - traceId
      additionalProperties: false
    AuthorizationDenied:
      type: object
      properties:
        _tag:
          type: string
          enum:
          - AuthorizationDenied
        reason:
          type: string
      required:
      - _tag
      - reason
      additionalProperties: false
x-refined-from:
- api-saperly-com-openapi.json
- saperly-openapi.yml