Skip to main content
Send the token as Authorization: Bearer dp_live_…. A token belongs to the organization in which it was created; sending an orgId does not switch workspaces.

Effective permissions

For each request, the API intersects token scopes with the creator’s current permissions, including configured role changes. The creator’s object assignments are applied by the corresponding inventory queries. GET /projects/{id}?include=properties requires both project:read and property:read. Object-scoped tokens cannot create new projects.

Lifecycle

Keep tokens out of browser code and public repositories. To rotate one, create a replacement, update the integration, and then revoke the old token. Expired or revoked tokens stop working. An inactive creator or suspended organization can also prevent requests. Check the returned error code.