v31

latestSwagger 2.0raw.githubusercontent.com2026-08-01119317529.5 KB
Rbac
Credentials
Project-Level

Create a project-level API token

Create a project-level API token associated with a Kargo Role virtual resource. Returns a Kubernetes Secret resource representing the token. Store it securely. The token is not retrievable via the Kargo API after creation except in a redacted form.

post/v1beta1/projects/{project}/roles/{role}/api-tokens

Path parameters

projectstring required

Project name

rolestring required

Role name

Request body

namestring

Response

Secret resource (k8s.io/api/core/v1.Secret)

apiVersionstring

APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources +optional

dataobject

Data contains the secret data. Each key must consist of alphanumeric characters, '-', '_' or '.'. The serialized form of the secret data is a base64 encoded string, representing the arbitrary (possibly non-string) data value here. Described in https://tools.ietf.org/html/rfc4648#section-4 +optional

immutableboolean

Immutable, if set to true, ensures that data stored in the Secret cannot be updated (only object metadata can be modified). If not set to true, the field can be modified at any time. Defaulted to nil. +optional

kindstring

Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds +optional

stringDataobject

stringData allows specifying non-binary secret data in string form. It is provided as a write-only input field for convenience. All keys and values are merged into the data field on write, overwriting any existing values. The stringData field is never output when reading from the API. +k8s:conversion-gen=false +optional

typestring

Used to facilitate programmatic handling of secret data. More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types +optional