VeroXM Docs

API Access

API Access is where you issue and revoke the bearer tokens that authenticate requests to the Content API. A project has no working API access at all until at least one token is issued here.

Issuing a token

Give the token a name (so you can identify it later - “Marketing site”, “Mobile app”) and choose its abilities: read, create, update, and delete. The token's value is shown once, at creation - store it somewhere safe, since VeroXM cannot show it again.

Using a token

Send it as a bearer token on every Content API request:

Authorization header
Authorization: Bearer <your-token>

Abilities are enforced per request

A token with only read can list and fetch content and media, but any create, update, or delete request it makes is rejected with a 403 and an explanation of which ability was missing.

Revoking a token

Revoke a token the moment it's no longer needed, or if it may have leaked. Revocation takes effect immediately - every subsequent request with that token is rejected as unauthorized.

Tokens are project-scoped

A token issued for one project cannot be used against another project's Content API, even within the same tenant.

Username/password credentials for end users

A static token is meant to live in a server you control. If the API needs to authenticate individual end users instead - a mobile app, a partner you don't operate - create a username/password credential here instead of a static token. The caller logs in against the project (see End-user login & refresh tokens) and gets back a short-lived access token plus a rotating refresh token, scoped to the same read/create/ update/delete abilities you choose here. Deleting the credential immediately invalidates every refresh token issued under it.

Exporting a Postman collection

This page can also generate a real Postman Collection Format v2.1 file built from the project's actual content models and its actual v1 and v2 routes - not a generic template. Every collection's endpoints are grouped into GET / POST / PATCH / DELETE folders with realistic example request bodies drawn from each field's type.

The exported collection includes an Auth folder with Login and Refresh requests wired to a test script: run Login once (with a username/password credential you created above, or paste a static token straight into the collection's apiKey variable) and every other request in the collection - already set to send Authorization: Bearer {{apiKey}} - starts working immediately, no manual copy-pasting a token between requests.

Use Download Postman Collection on this page to get the file, then import it into Postman (or any client that reads the v2.1 collection format).