Create a token
Open API Tokens, create a token, and copy it securely. The full token is shown only when it is created. The token belongs to your user account and can access projects that account belongs to. Location endpoints also check the project’s API access and the token’s permissions.Send the token
Authorization: Bearer, not an X-API-Key header or a token in the URL. Keep tokens in server-side integrations and out of public website code.
For JSON request bodies, also send Content-Type: application/json.
Location permissions
Select the permissions your integration needs when creating its token. Revoke an unused or compromised token from the same API Tokens page.
Authentication errors
A missing, expired, revoked, or invalid token returns401:
403. A project or location outside your access returns 404. See errors.