> For the complete documentation index, see [llms.txt](https://documentation.connexica.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.connexica.com/api/01.-api-tokens.md).

# 01. API Tokens

Personal API tokens authenticate requests to the CXAIR API (`/api/v1`). Each token acts with the permissions of the user that created it — it can only see the indexes, reports and features that user can access.

## Create a token

{% stepper %}
{% step %}

### Open the API Tokens tab

Open **Preferences** and select the **API Tokens** tab.
{% endstep %}

{% step %}

### Name the token

Enter a **Label** that identifies where the token will be used, for example `CI Pipeline`.
{% endstep %}

{% step %}

### Set an expiry

Optionally enter an **Expiry** in days. Leave blank for a token that does not expire.
{% endstep %}

{% step %}

### Select scopes

Select only the **Scopes** the integration requires. `Query Execute` is selected by default.
{% endstep %}

{% step %}

### Create and copy

Select **Create Token** and copy the token value immediately. The full value is shown once only and cannot be retrieved later.
{% endstep %}
{% endstepper %}

## Scopes

| Scope           | UI label      | Allows                                                                        |
| --------------- | ------------- | ----------------------------------------------------------------------------- |
| `query:execute` | Query Execute | `QUERIES.EXECUTE`, `CROSSTAB.EXECUTE`                                         |
| `indexes:read`  | Indexes Read  | `INDEXES.FIND`                                                                |
| `reports:read`  | Reports Read  | `REPORTS.FIND`, `REPORTS.LOAD`, `PAGES.REPORTS.PLACEHOLDERS.LIST`             |
| `reports:write` | Reports Write | `REPORTS.COPY`, `PAGES.REPORTS.*` write methods, and the `saveReport` options |

Grant the minimum scopes required — a query-only integration does not need report write access.

## Manage tokens

The API Tokens tab lists each token's prefix, scopes, creation and expiry dates, last-used time and status (**Active**, **Expired** or **Revoked**).

Select **Revoke** to disable a token immediately. Revocation cannot be undone.

Tokens are stored hashed; only their prefix is shown after creation. If a token value is lost, revoke it and create a new one.
