Customer
Back to marketplace

Customer · Marketplace · API access

Marketplace integration tokens.

The credentials that sync catalog feeds, validate against the sandbox, and pull analytics from the marketplace. Each row shows a masked prefix and a SHA-256 fingerprint. The secret half is never returned by the API, so this view cannot leak it. Revoke and rotation happen on the Developer console.

Access tokens

Simulated
Marketplace access tokens with label, masked prefix, SHA-256 fingerprint, scopes, state, creation date, last use with source IP, 30 and 90-day call counts, and expiry.
TokenPrefixFingerprintScopesStateLast usedUsage 30dExpires
Catalog sync (prod)created May 2, 2026naas_live_••••4f2a9f1a3c5e7b0d...0f2a
  • catalog:read
  • offers:write
  • sync:run
State: Active67d ago203.0.113.421,240 (3,880/90d)No expiry
Sandbox validationcreated Jun 18, 2026naas_test_••••c71ea1b2c3d4e5f6...d5e6
  • sandbox:run
  • quotes:read
State: Active67d ago198.51.100.7410 (1,320/90d)No expiry
Analytics pull (read-only)created Mar 11, 2026naas_live_••••9d33f0e1d2c3b4a5...6677
  • analytics:read
State: Expiring69d ago203.0.113.1892 (276/90d)Aug 14, 2026

Why no secrets here

The API returns token metadata only: a masked prefix so you can confirm which token a client is using, and a SHA-256 fingerprint so you can verify a deployed credential without transmitting it. The raw token value is write-only. It is shown once at creation time on the Developer console and is never retrievable after. Revoke, rotate, and scope changes all happen there.