Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Kong Personal Access Tokens API

The Personal Access Tokens API from Kong — 3 operation(s) for personal access tokens.

Kong Personal Access Tokens API is one of 139 APIs that Kong publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 1 JSON Schema definition.

Tagged areas include Personal Access Tokens. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, a JSON-LD context, a GitHub repository, an API reference, authentication docs, and 1 JSON Schema.

This API exposes 6 operations across 3 paths, and defines 28 schemas. It is described by OpenAPI 3.1.0, at version 3.14.0.

Requests are made against a single base URL, {protocol}://{hostname}:{port}{path}.

6 operations 3 paths 28 schemas 1 DELETE2 GET2 PATCH1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
3.14.0
Base URL
https://konghq.com/
Authentication
API Key
Contact
License
Resource Areas
1

Authentication & Security 1

Kong Personal Access Tokens API declares 1 security scheme for authenticating requests. An API key is passed in the header as Kong-Admin-Token (adminToken). By default, every request must be authenticated.

Paths & Operations 6

Across 3 paths, the API surfaces 6 operations — 1 DELETE, 2 GET, 2 PATCH, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Personal Access Tokens 6
GET
/v3/users/{userId}/access-tokens
List PATs
list-users-personal-access-tokens 1 param → 200400401403404
POST
/v3/users/{userId}/access-tokens
Create a new personal access token
create-personal-access-token 1 param body → 201400401403404409
GET
/v3/users/{userId}/access-tokens/{tokenId}
Get Personal Access Token details
get-personal-access-token-details 2 params → 200400401403404
PATCH
/v3/users/{userId}/access-tokens/{tokenId}
Update personal access token details
update-personal-access-token-details 2 params body → 200400401403404
DELETE
/v3/users/{userId}/access-tokens/{tokenId}
Delete personal access token
delete-personal-access-token 2 params → 204400401403404
PATCH
/v3/users/{userId}/access-tokens/{tokenId}/revoke
Revoke Personal Access Token
revoke-personal-access-token 2 params → 200400401403404

Schemas 28

The contract defines 28 schemas that model the data the API accepts and returns. The most detailed are PersonalAccessTokenCreateResponse (11 properties), PersonalAccessToken (10 properties), InvalidParameterChoiceItem (5 properties), InvalidParameterMinimumLength (5 properties). Each schema is shown below with its type and property counts.

InvalidParameterMinimumLength
object
5 properties 4 required
PersonalAccessTokenCreateRequestWithExpiresAt
object
Deprecated: Use ttlseconds instead of expiresat to specify token expiration. Using a time-to-live value avoids clock skew issues when setting token expiration.
2 properties 2 required
UpdatedAt
string
An ISO-8601 timestamp representation of entity update date.
ConflictError
InvalidParameterChoiceItem
object
5 properties 4 required
InvalidParameterMaximumLength
object
5 properties 4 required
PersonalAccessTokenCreateRequestWithTTL
object
2 properties 2 required
UUID
string
Contains a unique identifier used for this resource.
UnauthorizedError
ForbiddenError
LastUsedAt
string
An ISO-8601 timestamp representation of entity last used date.
PersonalAccessTokenCreateResponse
object
Details of the created personal access token.
11 properties 7 required
RevokedBy
string
Contains a unique identifier used for the user that revoked this token.
PersonalAccessTokenState
string
State of the personal access token.
CreatedAt
string
An ISO-8601 timestamp representation of entity creation date.
BaseError
object
standard error
5 properties 4 required
InvalidParameterDependentItem
object
5 properties 4 required
InvalidRules
string
invalid parameters rules
PersonalAccessToken
object
Properties of a personal access token.
10 properties 7 required
ExpiresAt
string
An ISO-8601 timestamp representation of entity expiration date.
InvalidParameters
array
invalid parameters
BadRequestError
InvalidParameterStandard
object
4 properties 2 required
RevokedAt
string
An ISO-8601 timestamp representation of entity revoked at date.
PATName
string
NotFoundError
PageMeta
object
Contains pagination query parameters and the total number of objects returned.
3 properties 3 required
UserId
string
Contains a unique identifier used for a user.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

kong-personal-access-tokens-api-openapi.yml Raw ↑

Other APIs Kong publishes across the network.

Kong Gateway
Kong AI Gateway
Kong Agent Gateway
Kong MCP Registry
Kong Context Mesh
Kong Mesh
Kong Insomnia
Kong ACLs API
Kong Add-Ons API
Kong API API
Kong API Attributes API
Kong API Documentation API