Dok.
Bla i dokumentasjonen

API authentication and tokens

Create API tokens for the Privatus Analytics REST API, choose permissions, sites, expiry and IP allowlists, and send them as Bearer tokens in requests.

Vis som Markdown

API tokens#

Create a token in Workspace settings → API tokens. Choose:

  • a name,
  • permissions: any subset of your own (for example only analytics.read for a dashboard integration),
  • sites: all your sites, or only some,
  • an optional expiry date,
  • an optional IP allowlist (IPv4/IPv6 addresses or CIDR ranges).

The token (pat_…) is shown once. We store only a SHA-256 digest and a short prefix so you can recognize it in the list.

http
Authorization: Bearer pat_…

Requests with a token don't use cookies or CSRF tokens.

What a token can do#

A token acts as the member who created it, narrowed by its settings:

  • permissions = the member's role ∩ the token's permissions,
  • sites = the member's site access ∩ the token's sites.

If the member loses access, so does the token. See the permission matrix. Each operation in the reference names the permission it needs.

A token belongs to one workspace. Using it on another workspace's resources returns 403.

Errors#

Status Code Meaning
401 unauthorized Missing, invalid, revoked or expired token
403 forbidden The token's IP allowlist doesn't include your IP, or the token lacks the permission or site

Revoking#

Revoke a token in the token list. Removing a member from a workspace revokes their tokens for it. The list shows when each token was last used.

Public endpoints#

A few operations need no token: the docs (including /docs/*.json), /openapi.json, and the collection endpoints (/api/event, /api/pixel, while /api/events uses an ingest key).

OAuth#

MCP clients can connect with OAuth 2.1 instead of a pasted token: see MCP authentication. OAuth-issued tokens are ordinary API tokens you can see and revoke in your token list.