Developer reference
Create and revoke API tokens
Use named minimum-scope credentials for integrations and keep their lifecycle separate from browser sessions.
Create a separate token for each integration. A descriptive name and minimum scopes make later review and revocation easier.
Create a read-only token
- Sign in to the intended Helm account.
- Open Settings → API tokens.
- Give the integration a recognizable name.
- Select
read:financefor a financial read-only client. - Copy the secret when shown and store it in your integration’s server-side secret store.
Use imports:read separately when the client needs import-job inspection. Do not add write or deletion permission for convenience.
Management endpoints
| Method | Path | Purpose |
|---|---|---|
| GET | /api/v1/api-tokens | List token metadata. |
| POST | /api/v1/api-tokens | Create a token. |
| DELETE | /api/v1/api-tokens/:id | Revoke an owned token. |
A Helm-token caller needs manage:tokens for these registered management operations. Metadata is not a way to retrieve an old secret.
Revoke or replace
Revoke a credential when its integration ends or it is exposed. Update the integration to a newly issued minimum-scope credential and verify its intended request. Do not keep a leaked token as a fallback.
Browser sign-out and API-token revocation are different actions. Signing out of one browser does not delete all integration tokens.
Never put a token in a URL, client bundle, screenshot or full request log. Continue with scopes and quickstart.