Skip to content

API tokens: what they can and cannot do

API tokens

API tokens: what they can and cannot do; Revoking an API token.

An API token lets a script do the things you would otherwise do in the app: add transfers, list your library, and work with files. It is created in the security section of your account page.

Using one

Authorization: Bearer gt_...

What it can reach

A token can add transfers, list your library and fetch files. It cannot change account settings, sessions, two-factor setup or billing. A leaked token cannot take over the account it belongs to.

It is shown once

The token value appears at the moment you create it and never again. gettor keeps only what it needs to verify one, not the token itself. If you lose it, revoke it and make another.

Careful: A token counts against the same plan limits you do. Automation that exceeds what one person would plausibly do is treated as unfair use.

Revoking an API token

Revoking takes effect on the next request, and cannot be undone.

Each token in the list has a revoke action. Once revoked it stops working immediately and permanently — there is no way to bring it back, so anything using it needs a new one.

Revoke immediately if

  • The token was committed to a repository, pasted into a chat, or included in a log.
  • You no longer run the script it was made for.
  • You cannot account for activity on your account.

Tip: Make one token per script rather than sharing one. Then revoking a leaked token breaks exactly one thing instead of everything.

Still need help?

Can't find what you need? Contact support.