API Access
API Access is where you issue and revoke the bearer tokens that authenticate requests to the Content API. A project has no working API access at all until at least one token is issued here.
Issuing a token
Give the token a name (so you can identify it later - “Marketing site”, “Mobile app”) and choose its abilities: read, create, update, and delete. The token's value is shown once, at creation - store it somewhere safe, since VeroXM cannot show it again.
Using a token
Send it as a bearer token on every Content API request:
Authorization: Bearer <your-token>Abilities are enforced per request
A token with only read can list and fetch content and media, but any create, update, or delete request it makes is rejected with a 403 and an explanation of which ability was missing.
Revoking a token
Revoke a token the moment it's no longer needed, or if it may have leaked. Revocation takes effect immediately - every subsequent request with that token is rejected as unauthorized.
Tokens are project-scoped
Username/password credentials for end users
A static token is meant to live in a server you control. If the API needs to authenticate individual end users instead - a mobile app, a partner you don't operate - create a username/password credential here instead of a static token. The caller logs in against the project (see End-user login & refresh tokens) and gets back a short-lived access token plus a rotating refresh token, scoped to the same read/create/ update/delete abilities you choose here. Deleting the credential immediately invalidates every refresh token issued under it.
Exporting a Postman collection
This page can also generate a real Postman Collection Format v2.1 file built from the project's actual content models and its actual v1 and v2 routes - not a generic template. Every collection's endpoints are grouped into GET / POST / PATCH / DELETE folders with realistic example request bodies drawn from each field's type.
The exported collection includes an Auth folder with Login and Refresh requests wired to a test script: run Login once (with a username/password credential you created above, or paste a static token straight into the collection's apiKey variable) and every other request in the collection - already set to send Authorization: Bearer {{apiKey}} - starts working immediately, no manual copy-pasting a token between requests.
Use Download Postman Collection on this page to get the file, then import it into Postman (or any client that reads the v2.1 collection format).