Skip to main content
API tokens are secure credentials that allow you to authenticate and interact with the Ankra platform programmatically. They are used for CLI operations, CI/CD automation, and integrating Ankra with your own tools or scripts.

How to Generate an API Token

  1. Click your profile icon in the bottom left corner of the Ankra dashboard.
  2. In the menu, select Profile.
  3. On your profile page, choose API Tokens.
  4. Click Create on the token list page.
  5. Give your token a descriptive name and, if an MCP client will use it, choose its MCP access.
  6. Copy the generated token and store it securely. You will not be able to view it again!
For security, create separate tokens for different use cases (e.g., CLI, CI/CD, integrations). A personal token acts as you; for automation that runs without a person behind it, create a service token with the narrowest role that does the job.

Creating a token from the CLI

ankra tokens manages the same tokens as the profile page, which is what you want in a script or a fresh CI runner.
The secret is printed once, at creation. -o json writes the whole answer - id, token, type, expiry - for a script to capture:
Revoking and deleting are two steps, and only revoking stops the token working. ankra tokens delete refuses a token that is still live: revoke it first, then delete it to remove the row. A revoked token is dead immediately, whatever it is stored in.

Scopes

A token created without --scopes is a REST token: it authenticates the CLI and every /api/v1 call your role permits. --scopes adds access to the MCP server, and is the only place scopes apply today.
An MCP-scoped token is bound to the organisation it was created in and refuses to act anywhere else: passing --org (or X-Ankra-Organisation-Id) with one is rejected rather than honoured. Create one token per organisation you want an MCP client to reach. A REST token accepts the override as usual.
A token never exceeds the role of the person who created it - roles and scopes decide what it may do, and a token created by a viewer stays read-only however it is used.

Tokens Ankra creates for you

Not every credential in the platform is one of these tokens, and the distinction matters when you are rotating something. Ankra-managed credentials appear in your organisation’s credential lists marked as managed; they cannot be edited there, only through the resource that owns them.

Use Cases for API Tokens

1. Ankra CLI Authentication

Set the ANKRA_API_TOKEN environment variable to authenticate the CLI:

2. CI/CD Integration

Use API tokens in your CI/CD pipelines to automate cluster management, addon deployment, or other Ankra API operations. Store tokens as secrets in your CI/CD system (e.g., GitHub Actions, GitLab CI, Jenkins). Example (GitHub Actions):

3. Programmatic Access (Source Code)

API tokens can be used in scripts or applications written in any language that supports HTTP requests (e.g., Python, Go, Node.js, Bash). Python Example:
Node.js Example:

Troubleshooting

  • Token not working? Double-check you copied it correctly and that it has the right permissions.
  • Lost your token? Revoke it, create a new one, then delete the old row.
  • Permission errors? A personal token acts with its owner’s role and a service token with the role it was given; an MCP client also needs the matching mcp: scope.

More Information