curl --request POST \
--url https://api.benchgen.com/api/tokens/ \
--header 'Content-Type: application/json' \
--cookie sessionid= \
--data '
{
"scopes": [
"models:read",
"knowledge:read"
],
"name": "CI pipeline",
"expires_in_days": 123
}
'import requests
url = "https://api.benchgen.com/api/tokens/"
payload = {
"scopes": ["models:read", "knowledge:read"],
"name": "CI pipeline",
"expires_in_days": 123
}
headers = {
"cookie": "sessionid=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: 'sessionid=', 'Content-Type': 'application/json'},
body: JSON.stringify({
scopes: ['models:read', 'knowledge:read'],
name: 'CI pipeline',
expires_in_days: 123
})
};
fetch('https://api.benchgen.com/api/tokens/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.benchgen.com/api/tokens/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'scopes' => [
'models:read',
'knowledge:read'
],
'name' => 'CI pipeline',
'expires_in_days' => 123
]),
CURLOPT_COOKIE => "sessionid=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.benchgen.com/api/tokens/"
payload := strings.NewReader("{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "sessionid=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.benchgen.com/api/tokens/")
.header("cookie", "sessionid=")
.header("Content-Type", "application/json")
.body("{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.benchgen.com/api/tokens/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["cookie"] = 'sessionid='
request["Content-Type"] = 'application/json'
request.body = "{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}"
response = http.request(request)
puts response.read_bodyCreate a token
The normal way to create a token is the web app: Profile Settings > Platform API tokens (you are signed in with your session there, nothing else is needed). Programmatic creation works only with an interactive credential: the sessionid cookie of a signed-in browser session, or an interactive token from POST /api/api-token-auth/. a platform token cannot mint tokens and gets 403, so a leaked token can never widen its own reach. The response carries token with the raw secret EXACTLY ONCE; only its hash is stored.
curl --request POST \
--url https://api.benchgen.com/api/tokens/ \
--header 'Content-Type: application/json' \
--cookie sessionid= \
--data '
{
"scopes": [
"models:read",
"knowledge:read"
],
"name": "CI pipeline",
"expires_in_days": 123
}
'import requests
url = "https://api.benchgen.com/api/tokens/"
payload = {
"scopes": ["models:read", "knowledge:read"],
"name": "CI pipeline",
"expires_in_days": 123
}
headers = {
"cookie": "sessionid=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: 'sessionid=', 'Content-Type': 'application/json'},
body: JSON.stringify({
scopes: ['models:read', 'knowledge:read'],
name: 'CI pipeline',
expires_in_days: 123
})
};
fetch('https://api.benchgen.com/api/tokens/', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.benchgen.com/api/tokens/",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'scopes' => [
'models:read',
'knowledge:read'
],
'name' => 'CI pipeline',
'expires_in_days' => 123
]),
CURLOPT_COOKIE => "sessionid=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.benchgen.com/api/tokens/"
payload := strings.NewReader("{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "sessionid=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.benchgen.com/api/tokens/")
.header("cookie", "sessionid=")
.header("Content-Type", "application/json")
.body("{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.benchgen.com/api/tokens/")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["cookie"] = 'sessionid='
request["Content-Type"] = 'application/json'
request.body = "{\n \"scopes\": [\n \"models:read\",\n \"knowledge:read\"\n ],\n \"name\": \"CI pipeline\",\n \"expires_in_days\": 123\n}"
response = http.request(request)
puts response.read_bodyAuthorizations
Interactive browser session, the sessionid cookie Django sets when you sign in to the web app (benchgen.com). To script this endpoint, sign in in a browser and copy the sessionid cookie from DevTools > Application > Cookies. The recommended path is simply the web app itself: Profile Settings > Platform API tokens. Platform tokens are deliberately refused here (403), so a leaked token can never mint successors.
Body
Scopes the token will carry, fixed at creation. admin is accepted only for staff accounts; internal:* scopes can never be minted through the API.
models:read, models:write, benchmark:read, benchmark:run, benchmark:create, benchmark:manage, benchmark:publish, knowledge:read, knowledge:write, billing:read, agents:chat, agents:manage, admin ["models:read", "knowledge:read"]
"CI pipeline"
Omit or 0 for no expiry, max 3650
Response
Created; token holds the secret, shown once