Skip to main content
All Workspace API requests authenticate with a personal access token. Include it as a Bearer token in the Authorization header with every request:
What the token needs:
  • It has to belong to the workspace you’re calling for. A token for another workspace is refused.
  • It needs Full access. A Read-only token is refused, even on the endpoints that only read.
  • Workspace API keys aren’t accepted.
A personal access token acts as you, so a request only succeeds if your own workspace role allows the action. Changing invitations and groups needs the owner or admin role. Listing groups and their members also works for editors.

Get an access token

To create a personal access token:
  1. In your workspace, click your workspace name at the bottom left, then click Settings.
  2. Click Secrets in the sidebar.
  3. Click the Personal access tokens tab.
  4. Click Create access token.
  5. Enter a Name, and under Permission, choose Full access.
  6. Click Create access token, then copy the value.
See Creating an access token for every option.
Your personal access token acts as your Base44 account. Treat it like a password, don’t share it, and don’t commit it to version control.

Example request