Skip to main content

Create a token

Open API Tokens, create a token, and copy it securely. The full token is shown only when it is created. The token belongs to your user account and can access projects that account belongs to. Location endpoints also check the project’s API access and the token’s permissions.

Send the token

Use Authorization: Bearer, not an X-API-Key header or a token in the URL. Keep tokens in server-side integrations and out of public website code. For JSON request bodies, also send Content-Type: application/json.

Location permissions

Select the permissions your integration needs when creating its token. Revoke an unused or compromised token from the same API Tokens page.

Authentication errors

A missing, expired, revoked, or invalid token returns 401:
A valid token without the required permission, or a project without API access, returns 403. A project or location outside your access returns 404. See errors.