Skip to main content
Back to Changelog
June 19, 2026
IAM

Personal API Tokens

Create, list, and revoke your own bearer tokens for scripting against the ZebraByte API, without sharing a service account with your team.

Personal API Tokens

Until now, calling the ZebraByte API outside the console meant either building an OAuth2 app or borrowing a token meant for something else.

Personal API tokens fix that. Head to /me/oauth-tokens in the console, and you can create a bearer token scoped to your own identity, list the tokens you’ve issued, and revoke any of them on the spot. Every v1 API scope is now registered and enforced, so tokens only work for what they were actually granted.

Auditors get the v1:iam:read scope by default, which covers the read-only API access most audit tooling needs without a separate request.

ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert