neosourceDocs
Search docs

List workspace access tokens

GET/api/orgs/{org}/tokens

listOrgTokens

Session-authenticated caller only. Admin/Owner only. Raw secrets are never returned.

Requires authentication using a session cookie — see tokens and scopes.

curl

curl -X GET 'https://neosource.dev/api/orgs/ORG/tokens' \
  -b 'ns_session=$NEOSOURCE_SESSION'

fetch

fetch("https://neosource.dev/api/orgs/ORG/tokens", {
  method: "GET",
  credentials: "include",
});

Path parameters

orgrequired

Organization slug.

string

Responses

200Tokens

application/json

OrgTokenListResponse

object

tokensrequired

array

items

OrgTokenResponse

object

created_atrequired

integerint64

expires_at

integer | nullint64

labelrequired

string

last_used_at

integer | nullint64

rolerequired
one of
scopesrequired

array

items

string

service_account_handlerequired

string

Handle of the service account that owns this token.

token_hint

string | null

token_idrequired

string

403Forbidden — one of: forbidden, needs_scope

application/json

one of
  • ErrorForbidden
  • NeedsScopeError

    object

    `403` body returned when listing private repos but the linked identity lacks the required provider scope. The SPA turns this into an incremental-authorization prompt (Tier 2) that calls the `/elevate` OAuth endpoint with this `scope`.

    errorrequired

    string

    Always `needs_scope` — this body exists to carry the extra fields that kind needs.

    "needs_scope"

    scoperequired

    string

    The provider scope to request via elevation (e.g. `"repo"`).

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 404Not Found — one of: not_found
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget

Schemas

Referenced above. Listed here rather than expanded inline, so the same definition is not repeated at every level.

WorkspaceRole

string

Workspace membership role. Ordered low → high (`Member < Admin < Owner`) so that `if actor_role >= WorkspaceRole::Admin` reads naturally.

"member""admin""owner"