API tokens

Create, store, rotate, and revoke tokens for supported integrations.

A personal token begins with sh_ and authenticates supported integrations, including the WordPress plugin and selected output-contract operations.

Create a token

  1. Open your account profile.
  2. Go to API tokens.
  3. Name the token after one specific integration.
  4. Copy the secret immediately.

The complete value is shown only once. SemanticHub stores a one-way hash and a short prefix used to identify the token in the application.

Use the token

Authorization: Bearer sh_your_token

Never place a token in a query string, browser-side code, source repository, error log, or prompt.

Rotate and revoke

Rotation invalidates the previous secret immediately. Rotate, update the integration, and test connectivity without delay. Revoke tokens that no longer have an owner or active integration.

Why the full OpenAPI schema is not public

The schema used to generate the frontend client also contains internal application and administrative endpoints. These docs describe the supported integration contract instead of exposing the complete application map.

All pages