API tokens
Programmatic access to the WebShield API with scoped permissions and per-domain binding.
API tokens give programmatic access to the API (CI/CD, monitoring, integrations) without a login. A token has configurable permissions (scopes) and an optional binding to a single domain, so a leak is limited to exactly what you allowed.
What tokens can and cannot do
Section titled “What tokens can and cannot do”A token never gets access to:
- account security (changing password/email, OAuth);
- managing tokens themselves (you cannot issue or revoke a token using only a token);
- billing write operations (payments, top-ups, plan changes, payers).
This is intentional: a token narrows the owner’s access and cannot escalate its own privileges.
Permissions (scopes)
Section titled “Permissions (scopes)”A scope is area:level. Write includes read.
| Area | Levels | What it grants |
|---|---|---|
| Domains | read / write | listing and managing domains, delegation |
| DNS | read / write | a domain’s DNS records |
| Proxy | read / write | proxying and edge host configuration |
| Sites | read / write | static sites (upload, publish) |
| Support | read / write | support tickets |
| Form protection | read / write | form protection projects and scoring calls |
| Analytics | read | domain statistics |
| Billing | read | invoices and usage (no payment operations) |
Domain binding
Section titled “Domain binding”When creating a token you can pick one domain — the token then works only with its resources (DNS, proxying, static sites, analytics, billing read for that domain). Requests to other domains are rejected. “All domains” removes the restriction within the chosen scopes. Support is not domain-bound.
Creating and revoking
Section titled “Creating and revoking”- Open Settings → API tokens.
- Set a name, pick permissions, optionally a domain and an expiry date (empty — non-expiring).
- Click Create token. The full token (
wsk_…) is shown once — save it immediately. - Revoke a token from the list; it stops working immediately.
The command-line client is what consumes the token — nothing else to set up, just put it in WS_TOKEN (or save it to a profile with webshield auth login):
export WS_TOKEN=wsk_…
webshield domains list # requires "Domains: read"webshield dns add example.com www A 203.0.113.10 # requires "DNS: write"webshield sites publish www.example.com --dir ./distIf the token lacks the scope or is bound to a different domain, the CLI reports the refusal (403); an invalid or expired token gives 401.