Spoar
Tokens

Create an API token

POST
/v2/tokens

Scope read, sql or admin, limited to projectIds or all projects when null. The token is in this response only.

Authorization

AuthorizationBearer <token>

An API token from POST /v2/tokens (at_live_...), or a project's secret key (sk_...) for server-side ingest.

In: header

Request Body

Leave projectIds out for every project and expiresAt out for no expiry; an expiry must be in the future.

TypeScript Definitions

Use the request body type in TypeScript.

Leave projectIds out for every project and expiresAt out for no expiry; an expiry must be in the future.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v2/tokens" \  -H "Content-Type: application/json" \  -d '{    "name": "GitHub Actions report",    "scope": "read",    "projectIds": [      "remcostoeten.nl"    ],    "expiresAt": "2027-09-27T00:00:00.000Z"  }'
{  "data": {    "id": "tok_01J8Z7",    "name": "GitHub Actions report",    "scope": "read",    "projectIds": [      "remcostoeten.nl"    ],    "token": "at_live_7c2e9f1a4b6d8e0c",    "expiresAt": "2027-09-27T00:00:00.000Z",    "createdAt": "2026-09-27T16:44:00.000Z"  }}