Overview
An API token authenticates the SDK, the CLI, and anything else that calls Cyberwave programmatically. A token is scoped to the workspaces you choose. It can act in those workspaces and no others, and the scope can be changed after the token is created without re-issuing it.Where to create one
Profile → Access
Your personal tokens. Lists every token you own or administer, and creates
user tokens.
Workspace settings → Tokens
Tokens that can act in that workspace, including service tokens. The
workspace you are viewing is always part of the scope.
Token types
User token
Acts as you, narrowed to its workspace scope. It stops working if your
account is removed — use it for scripts you run yourself.
Service token
Acts with its own role rather than yours, so it keeps working after you
leave the workspace. Use it for anything long-lived: CI, an edge deployment,
a scheduled job.
Choosing a role for a service token
A service token carries a role you pick — Reader, Developer, Writer or Admin. That role is a ceiling: the token can never do more than it allows, including on objects the token itself created. Lowering it takes effect immediately. You cannot give a token a role above your own, and you must be an admin of every workspace you scope a service token to. A plain user token only needs membership — it acts as you and can never exceed your own access.Scoping a token
Select one or more workspaces when you create the token. Creating from a workspace’s own settings locks that workspace into the scope; you can still add others. To change the scope later, use Edit scope on the token’s row. Removing a workspace takes effect immediately. Adding one requires membership there for a user token, or admin for a service token.Creating a new workspace does not extend any existing token to it. A token’s
reach only grows when you explicitly add a workspace to its scope.
Naming a workspace on every request
Requests say which workspace they act in. A token scoped to exactly one workspace resolves on its own, so nothing changes for single-workspace tokens. With a token scoped to several, a request that does not name one — and cannot infer it from the object it references — is rejected with400 workspace_required, listing the workspaces the token holds.
Set the workspace once on the client rather than per call: