API & Developers

Create and use API tokens

Project API tokens let an integration work with one DeployMonitor project. Treat every token as a secret because newly created tokens can read project data, create environments and logs, and manage maintenance.

Create a token

You need a Developer or Admin role on at least one project.

  1. Open Settings > API Tokens.

  2. Enter a recognizable Token name, such as Production deploy hook.

  3. Choose the Project.

  4. Select Create token.

  5. Copy the token immediately.

The plain token is displayed only when it is created. DeployMonitor cannot show it again later. Store it in a password manager or deployment secret store. Never commit it, place it in client-side code, or print it in logs.

Understand token scope

Every token is assigned to one project and receives these abilities:

  • project:read retrieves the assigned project.

  • project_environments:read lists and retrieves the project's environments.

  • project_environments:create creates non-primary environments for the project.

  • project_logs:read lists and retrieves the project's logs.

  • project_logs:create creates logs for the project.

  • project_maintenances:read retrieves current maintenance and maintenance history.

  • project_maintenances:write creates, updates, ends, and cancels project maintenance.

The project scope and abilities cannot be changed from API token settings after creation. Create another token for a different project.

The token owner's current project access still applies. The token loses access when its owner loses access to the project. Creating environments or logs and changing maintenance also stop when the owner no longer has a Developer or Admin role.

Authenticate requests

Send the token as a Bearer token and request JSON responses:

Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json

Use Content-Type: application/json for requests with a JSON body.

Review and revoke tokens

The API Tokens page lists each token's project, creation time, and last-used time. A token that has not authenticated a request displays Never used.

Select Revoke, review the token name, and confirm Revoke token to disable it immediately. Update the connected integration before or immediately after revocation to avoid failed requests.

Next, see Get the project assigned to a token, Manage project environments with the API, or Manage project maintenance with the API.