> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/tools/api-tokens/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # API Tokens > Create and manage organization-level API tokens for the IBEE public API, scoped to the entire organization or specific workspaces, and S3 credentials for Object Storage. API tokens give you programmatic access to IBEE Solutions services. Tokens are managed at the **organization level**: in the portal sidebar, click **API Tokens** under **Organization**. Only organization **Admins** can see and manage this page. The page has these tabs: | Tab | What you create there | | -------------------------- | --------------------------------------------------------------------------------------------------------------------- | | **API Tokens** | Bearer tokens for the IBEE REST API, CLI, and SDKs — scoped to the **Entire Organization** or **Specific Workspaces** | | **S3 Credentials** | Access Key ID and Secret Access Key for one workspace's Object Storage, for S3-compatible tools | | **Registry access tokens** | Tokens for Docker and OCI clients to access a container registry | | **Email Tokens** | Send-only tokens for one verified sending domain. Shown only when Email Service is enabled for your organization. | This page covers **API Tokens** and **S3 Credentials**. ## Before you begin * An active IBEE Solutions organization ([Create an organization](/docs/getting-started/account-setup/create-a-project)) * A verified identity ([Verify your identity](/docs/getting-started/account-setup/verify-account)) > **Info** > > Identity verification is required to create API tokens. If you haven't verified, the **Create API Token** button shows **Verify Identity** and redirects to the verification page. ## Create a token ### Go to API Tokens In the portal sidebar, click **API Tokens** under **Settings**. The page shows two tabs: **API Tokens** (platform tokens) and **S3 Credentials**. ### Open the create dialog Click **Create API Token**. ### Enter a name | Field | Required | Description | | ----- | -------- | ----------------------------------------------------------------------- | | Name | Yes | Identifies the token (max 100 characters), e.g. "Production automation" | ### Choose an access policy Select one of three access policies from the **Access policy** dropdown. #### Entire Organization The token has access to **all workspaces** in the organization. Choose this for organization-wide API automation. Set permissions for each resource: | Resource | Read | Edit | | ------------------ | ------------------------------ | ---------------------------------------- | | **GPU VMs** | View GPU virtual machines | Create, modify, delete GPU VMs | | **Cloud VMs** | View cloud virtual machines | Create, modify, delete Cloud VMs | | **Object Storage** | View Object Storage | Create, modify, delete storage resources | | **Load Balancer** | View load balancers | Create, modify, delete load balancers | | **Secret Manager** | View secrets | Create, modify, delete secrets | | **Billing** | View invoices, orders, balance | No edit permission (read only) | Select **Read** and/or **Edit** for each resource. At least one permission must be selected. Set a **Token expiration**: No expiration, 7 days, 30 days, 90 days, or 1 year. #### Specific Workspaces The token is scoped to **selected workspaces** only. After choosing this policy, a workspace selector appears — pick one or more workspaces. Permissions and expiration options are the same as Entire Organization, but the token only works within the selected workspaces. #### S3 Buckets Creates **S3-compatible credentials** (Access Key ID + Secret Access Key) for a specific workspace's Object Storage. Use this policy when you need S3 credentials for AWS CLI, rclone, or any S3-compatible client. 1. **Select a workspace** (required) — the workspace whose Object Storage this credential accesses. 2. **Choose a permission level:** | Permission | What it allows | | ----------------------- | -------------------------------------------------------------------------------------- | | **Admin Read & Write** | Create, list, delete buckets; edit bucket configuration; read, write, and list objects | | **Admin Read only** | List buckets; view configuration; read and list objects | | **Object Read & Write** | Read, write, and list objects in selected buckets | | **Object Read only** | Read and list objects in selected buckets | 3. **Specify bucket scope** (for Object Read & Write / Object Read only): * **Apply to all buckets in the selected workspace** (including newly created buckets) * **Apply to specific buckets only** — a bucket selector appears to pick individual buckets ### Create the token Click **Create API Token** (for platform tokens) or **Create Credential** (for S3). ### Save your credentials After creation, credentials are displayed once. Copy them immediately. #### Platform tokens (Entire Organization / Specific Workspaces) | Credential | Format | Use | | ------------ | ------------- | -------------------------------------------- | | Bearer Token | `ibee_v4_...` | `Authorization` header for the IBEE REST API | #### S3 credentials | Credential | Format | Use | | ----------------- | ------------------------------------------- | ---------------------------------------------------------- | | Access Key ID | `AKIA...` | S3 credential for AWS CLI, rclone, and S3-compatible tools | | Secret Access Key | Shown once only | S3 credential — copy immediately | | S3 Endpoint | `https://WORKSPACE-ID.blob.ibeestorage.com` | S3-compatible endpoint URL for the workspace | > **Warning** > > **Copy your credentials now.** The Secret Access Key and Bearer Token are not shown again. If you lose them, revoke the token and create a new one. ## Manage tokens The API Tokens page has two tabs: * **API Tokens** — lists platform tokens (Entire Organization and Specific Workspaces) * **S3 Credentials** — lists S3 credentials, with a workspace filter dropdown Each token shows: | Column | Description | | -------- | ------------------------- | | NAME | Token name | | PRODUCTS | Permission scopes granted | | CREATED | Creation date | | EXPIRES | Expiry date (or "Never") | | STATUS | Active / Expired | | ACTIONS | Revoke | ## Revoke a token Click **Revoke** in the Actions column. Revoked tokens lose access immediately and cannot be restored. Create a new token if access is needed again. ## Use S3 credentials with tools ### AWS CLI ```bash aws configure set aws_access_key_id YOUR-ACCESS-KEY-ID aws configure set aws_secret_access_key YOUR-SECRET-ACCESS-KEY aws configure set default.region us-east-1 # List buckets aws s3 ls --endpoint-url https://WORKSPACE-ID.blob.ibeestorage.com ``` ### rclone ```ini [ibee] type = s3 provider = Other access_key_id = YOUR-ACCESS-KEY-ID secret_access_key = YOUR-SECRET-ACCESS-KEY endpoint = https://WORKSPACE-ID.blob.ibeestorage.com ``` ## Troubleshooting **Create API Token button shows "Verify Identity"** Complete [identity verification](/docs/getting-started/account-setup/verify-account) before creating tokens. **Create button is disabled** At least one permission must be selected. For Specific Workspaces, select at least one workspace. For S3, select a workspace. **Secret Access Key not saved** The Secret Access Key is shown once only. Revoke the credential and create a new one. **S3 authentication failing** Verify you are using: * The correct **S3 Endpoint**: `https://WORKSPACE-ID.blob.ibeestorage.com` * The **Access Key ID** and **Secret Access Key** from the same credential ## Related pages * [Object Storage API Credentials](/docs/infrastructure/object-storage/api-tokens) * [Create a bucket](/docs/infrastructure/object-storage/buckets) * [Permissions and policies](/docs/infrastructure/object-storage/buckets/bucket-policies) > Create and manage organization-level API tokens for the IBEE public API, scoped to the entire organization or specific workspaces, and S3 credentials for Object Storage.