Create an API token
UserApiToken
Create an API token
Generates a new API token for the authenticated admin user. Accepts optional name, expiresAt, and isReadOnly fields in the request body. The raw token value is returned only once in the response and cannot be retrieved later. Requires ADMIN_TENANT permission.
POST
Create an API token
Authorizations
Server-to-server authentication. Generate a token in the admin UI at
Settings → Developers → API Access. Send the raw token in the
Api-Token header — there is no Bearer prefix.
Tokens can be marked read-only at creation time, in which case the API
rejects any non-GET request with 403 Forbidden.

