Authentication and tokens
Make an API token in Settings and send it with every request.
Every API request needs a token in its Authorization header (API overview sets up
$NIFTY_URL and $NIFTY_TOKEN):
curl "$NIFTY_URL/api/v1/people" -H "Authorization: Bearer $NIFTY_TOKEN"
Make a token
- Open Settings → API tokens.
- Choose New token (or press N).
- Give it a Name, so you can tell tokens apart, and choose when it Expires: Never, or in 30, 90 or 365 days.
- Choose Save.
- Copy the token, starting
nw_. Nifty shows it only once: if you lose it, revoke it and make another.
A token can read and change all your data, so treat it like a password. Each token in the list shows when it was last used and when it expires.
Revoke a token
- In Settings → API tokens, choose the bin beside the token.
- Choose Revoke token.
Apps using it stop working at once. Changing your password doesn't revoke tokens, nor does recovery.
What a token can't do
Your password, username and API tokens are managed only in Nifty itself, so a stolen token can't lock you out or make
more tokens. Those endpoints answer a token with 403 session_required, and they're left out of the reference.
When it's refused
A missing, unknown, expired or revoked token gets 401 unauthorized:
{ "error": { "code": "unauthorized", "message": "This token isn't valid." } }
When a token was sent, the response also has WWW-Authenticate: Bearer realm="Nifty", error="invalid_token". See
Errors.