Back to marketplace
Customer · Marketplace · API access
Marketplace integration tokens.
The credentials that sync catalog feeds, validate against the sandbox, and pull analytics from the marketplace. Each row shows a masked prefix and a SHA-256 fingerprint. The secret half is never returned by the API, so this view cannot leak it. Revoke and rotation happen on the Developer console.
- Tokens32 active
- Expiring1rotate before expiry
- Revoked0no longer accepted
- Calls / 30d1,7425,476 over 90d
Access tokens
Simulated| Token | Prefix | Fingerprint | Scopes | State | Last used | Usage 30d | Expires |
|---|---|---|---|---|---|---|---|
| Catalog sync (prod) | naas_live_••••4f2a | 9f1a3c5e7b0d...0f2a |
| State: Active | 67d ago203.0.113.42 | 1,240 (3,880/90d) | No expiry |
| Sandbox validation | naas_test_••••c71e | a1b2c3d4e5f6...d5e6 |
| State: Active | 67d ago198.51.100.7 | 410 (1,320/90d) | No expiry |
| Analytics pull (read-only) | naas_live_••••9d33 | f0e1d2c3b4a5...6677 |
| State: Expiring | 69d ago203.0.113.18 | 92 (276/90d) | Aug 14, 2026 |
Why no secrets here
The API returns token metadata only: a masked prefix so you can confirm which token a client is using, and a SHA-256 fingerprint so you can verify a deployed credential without transmitting it. The raw token value is write-only. It is shown once at creation time on the Developer console and is never retrievable after. Revoke, rotate, and scope changes all happen there.