API Tokens
API Tokens provide secure, authenticated access to Karyam APIs.
They allow external applications, scripts, CI/CD pipelines, and integrations to interact with Karyam programmatically without requiring interactive user authentication.
API Tokens are personal access tokens associated with an individual user account.
Why API Tokens Exist
Section titled “Why API Tokens Exist”While most users interact with Karyam through the web interface, many organizations need to integrate Karyam into existing systems and automation workflows.
Common use cases include:
- CI/CD pipelines
- Internal developer portals
- Automation scripts
- External applications
- Custom dashboards
- Third-party integrations
API Tokens make these integrations possible.
Creating an API Token
Section titled “Creating an API Token”API Tokens can be generated from your user profile.
Navigate to:
User Profile ↓API Tokens ↓Create API TokenToken Expiration
Section titled “Token Expiration”When creating a token, you can configure how long it remains valid.
Supported options include:
- Custom expiration durations
- No expiration
Example:
7 days30 days90 daysNever expiresThe selected expiration time determines when the token automatically becomes invalid.
Token Rotation
Section titled “Token Rotation”Generating a new API token automatically invalidates all previously issued tokens for that user.
This ensures only one active personal access token exists at a time and simplifies credential management.
Generate New Token ↓Previous Tokens Revoked ↓New Token ActivatedUsing API Tokens
Section titled “Using API Tokens”Karyam APIs use Bearer Token authentication.
Pass your API token using the Authorization header:
Authorization: Bearer <your_api_token>Example:
curl https://your-karyam-instance/api/v1/agents \ -H "Authorization: Bearer YOUR_API_TOKEN"Security Recommendations
Section titled “Security Recommendations”API Tokens provide the same permissions as the user who generated them.
Because of this, tokens should be treated as sensitive credentials.
Recommended practices include:
- Store tokens in secret managers.
- Rotate tokens regularly.
- Avoid embedding tokens directly in source code.
- Use expiration dates whenever possible.
- Revoke tokens immediately if they are exposed.
RBAC Integration
Section titled “RBAC Integration”API Tokens inherit the permissions of their owner.
For example:
Admin Token ↓Full Administrative Access
Developer Token ↓Developer Permissions
User Token ↓User PermissionsAPI Tokens do not bypass RBAC restrictions.
All authorization checks continue to apply.
Relationship to Other Concepts
Section titled “Relationship to Other Concepts”User ↓RBAC Role ↓API Token ↓Karyam APIThe token acts as an authenticated representation of the user who created it.
Common Use Cases
Section titled “Common Use Cases”Organizations commonly use API Tokens for:
- Triggering AI Flows from external systems
- Executing Agents programmatically
- Automating approvals
- Integrating internal applications
- Building custom user interfaces
- Creating operational dashboards
The Karyam Philosophy
Section titled “The Karyam Philosophy”AI systems should integrate naturally into existing business processes.
API Tokens allow organizations to extend Karyam beyond the user interface and into their broader technology ecosystem.
