owner or admin role
can create and manage tokens for their account and current platform. An API
token cannot manage other tokens, even when it is attached to an owner or admin
user.
Name the token so that its integration is easy to identify, then copy the
secret from the creation confirmation. The secret is displayed only once and
cannot be retrieved later.
Prefix the token with
Bearer in the Authorization header:
For example:
Security
All API requests must be made over HTTPS. Calls made over plain HTTP will fail.Token lifecycle
API tokens do not expire automatically. An owner or admin can pause a token, resume it, or delete it from the API Integration page in Hermes. Pausing is reversible; deleting is permanent. Both changes apply to subsequent requests without a deployment. To replace a lost or compromised token, create a new one, update the integration, and then delete the old token.Error Handling
If authentication fails, you will receive a401 Unauthorized response. Make
sure the token belongs to the correct account and platform, is active, and is
formatted with the Bearer prefix.