API tokens: what they can and cannot do
API tokensAPI tokens: what they can and cannot do; Revoking an API token.
An API token lets a script do the things you would otherwise do in the app: add transfers, list your library, and work with files. It is created in the security section of your account page.
Using one
Authorization: Bearer gt_...
What it can reach
A token can add transfers, list your library and fetch files. It cannot change account settings, sessions, two-factor setup or billing. A leaked token cannot take over the account it belongs to.
It is shown once
The token value appears at the moment you create it and never again. gettor keeps only what it needs to verify one, not the token itself. If you lose it, revoke it and make another.
Careful: A token counts against the same plan limits you do. Automation that exceeds what one person would plausibly do is treated as unfair use.
Revoking an API token
Revoking takes effect on the next request, and cannot be undone.
Each token in the list has a revoke action. Once revoked it stops working immediately and permanently — there is no way to bring it back, so anything using it needs a new one.
Revoke immediately if
- The token was committed to a repository, pasted into a chat, or included in a log.
- You no longer run the script it was made for.
- You cannot account for activity on your account.
Tip: Make one token per script rather than sharing one. Then revoking a leaked token breaks exactly one thing instead of everything.