Skip to content
WebShield Docs

API tokens

Programmatic access to the WebShield API with scoped permissions and per-domain binding.

API tokens give programmatic access to the API (CI/CD, monitoring, integrations) without a login. A token has configurable permissions (scopes) and an optional binding to a single domain, so a leak is limited to exactly what you allowed.

A token never gets access to:

  • account security (changing password/email, OAuth);
  • managing tokens themselves (you cannot issue or revoke a token using only a token);
  • billing write operations (payments, top-ups, plan changes, payers).

This is intentional: a token narrows the owner’s access and cannot escalate its own privileges.

A scope is area:level. Write includes read.

Area Levels What it grants
Domains read / write listing and managing domains, delegation
DNS read / write a domain’s DNS records
Proxy read / write proxying and edge host configuration
Sites read / write static sites (upload, publish)
Support read / write support tickets
Form protection read / write form protection projects and scoring calls
Analytics read domain statistics
Billing read invoices and usage (no payment operations)

When creating a token you can pick one domain — the token then works only with its resources (DNS, proxying, static sites, analytics, billing read for that domain). Requests to other domains are rejected. “All domains” removes the restriction within the chosen scopes. Support is not domain-bound.

  1. Open Settings → API tokens.
  2. Set a name, pick permissions, optionally a domain and an expiry date (empty — non-expiring).
  3. Click Create token. The full token (wsk_…) is shown once — save it immediately.
  4. Revoke a token from the list; it stops working immediately.

The command-line client is what consumes the token — nothing else to set up, just put it in WS_TOKEN (or save it to a profile with webshield auth login):

Terminal window
export WS_TOKEN=wsk_…
webshield domains list # requires "Domains: read"
webshield dns add example.com www A 203.0.113.10 # requires "DNS: write"
webshield sites publish www.example.com --dir ./dist

If the token lacks the scope or is bound to a different domain, the CLI reports the refusal (403); an invalid or expired token gives 401.