> For the complete documentation index, see [llms.txt](https://docs.reach-book.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.reach-book.com/developers/get-started/authentication.md).

# Create an API token

Tokens belong to one workspace and only carry the abilities you choose. Workspace administrators create them.

![Automation & API, where tokens and webhooks are created](https://1763342903-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMRRu0745JBUmVfpzClKv%2Fuploads%2Fgit-blob-1daf5b3ab278fdc340147ebc2bb3a1eda78e8d76%2Fautomation.webp?alt=media)

1. Open **Workspace settings → Automation & API** and choose **Create token**.
2. Pick only the abilities it needs (see the table below).
3. Give it an expiry date up to one year away.
4. Copy the token right away. It starts with `rbk_` and is shown only once.

## Abilities

| Ability            | Lets the token                                                                      |
| ------------------ | ----------------------------------------------------------------------------------- |
| `prospects:read`   | List and read prospects and groups                                                  |
| `prospects:write`  | Create and update prospects, and add or remove them from groups                     |
| `prospects:delete` | Delete prospects                                                                    |
| `outcomes:write`   | Record sales outcomes, meetings and opportunity values                              |
| `campaigns:read`   | Read the token creator's campaigns and their results                                |
| `campaigns:write`  | Add prospects to the token creator's draft campaigns, and pause or resume campaigns |
| `dnc:read`         | Read the do-not-contact list                                                        |
| `dnc:write`        | Add to and remove from the do-not-contact list                                      |
| `members:read`     | List workspace members and their roles                                              |

`GET /token` works with any valid token.

Revoke a token in the same place when it's no longer needed. Abilities can't be changed after a token is created: create a new token instead.

A token stops working when the administrator who created it loses admin access, or when the workspace is suspended.

## Sending the token

Send it in the `Authorization` header on every request:

```http
Authorization: Bearer rbk_YOUR_TOKEN
Accept: application/json
```
