> ## Documentation Index
> Fetch the complete documentation index at: https://astronomer.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an API token

> Retrieve information about a specific API token.



## OpenAPI

````yaml /astro/api/v-1-beta-1/iam/openapi.yaml get /organizations/{organizationId}/tokens/{tokenId}
openapi: 3.0.3
info:
  contact: {}
  description: Astro Identity and Access Management (IAM) API
  title: Astro Identity and Access Management (IAM) API
  version: v1beta1
servers:
  - url: https://api.astronomer.io/iam/v1beta1
security:
  - JWT: []
tags:
  - description: >-
      The `user` object represents a user account in your Astro Organization.
      Astro creates a new `user` object whenever you invite a user by email or
      add a user to Astro through an identity provider. The object contains all
      information about a user, including their personal information, roles, and
      login attempts. It doesn't include attributes for actions that the user
      completes after they log in, such as updating a Deployment. Make requests
      to `user` endpoints to manage permissions for existing users both at the
      Organization and Workspace level. To create new users, make requests to
      `invite` endpoints instead.
    name: User
  - description: >-
      The `team` object represents an Astro Team, which is a group of users that
      share the same permissions across your Organization and Workspaces. Make
      requests to `team` endpoints to create, update, and delete Teams across an
      Organization. See [Configure Teams on
      Astro](https://astronomer.io/docs/astro/manage-teams).
    name: Team
  - description: >-
      The `apitoken` object represents a single API token within your
      Organization. API tokens are used to authenticate automated tools and
      processes to your Organization. They have varying levels of access to your
      resources based on their Organization, Workspace, and Deployment roles.
      See [Workspace API tokens](workspace-api-tokens.md) and [Organization API
      tokens](organization-api-tokens.md).
    name: api-token
    x-group: API Token
  - description: >-
      The `invite` object represents the record of a user invite generated by
      Astro. It includes information both about the inviter and the invitee.
      Invites can be generated both by manual invitations through the Astro UI
      and automatic invitations through an identity provider. An `invite` record
      persists until its associated invite expires. Make requests to `invite`
      endpoints to create, delete, or audit invites for users across your
      Organization. See [Manage Organization
      users](https://astronomer.io/docs/astro/manage-organization-users) and
      [Manage Workspace
      users](https://astronomer.io/docs/astro/manage-workspace-users).
    name: Invite
  - name: allowed-ip-address-range
    x-group: Allowed IP Address Range
  - name: agent-token
    x-group: Agent Token
paths:
  /organizations/{organizationId}/tokens/{tokenId}:
    get:
      tags:
        - api-token
      summary: Get an API token
      description: Retrieve information about a specific API token.
      operationId: GetApiToken
      parameters:
        - description: >-
            The ID of the Organization where you want to retrieve token
            information.
          in: path
          name: organizationId
          required: true
          schema:
            type: string
        - description: The ID of the token that you want to retrieve data for.
          in: path
          name: tokenId
          required: true
          schema:
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiToken'
          description: OK
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Forbidden
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Not Found
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: Internal Server Error
      security:
        - JWT: []
components:
  schemas:
    ApiToken:
      properties:
        createdAt:
          description: >-
            The time when the API token was created in UTC, formatted as
            `YYYY-MM-DDTHH:MM:SSZ`.
          example: '2022-11-22T04:37:12Z'
          format: date-time
          type: string
        createdBy:
          $ref: '#/components/schemas/BasicSubjectProfile'
        description:
          description: The description of the API token.
          example: my token description
          type: string
        endAt:
          description: >-
            The time when the API token expires in UTC, formatted as
            `YYYY-MM-DDTHH:MM:SSZ`.
          example: '2022-11-22T04:37:12Z'
          format: date-time
          type: string
        expiryPeriodInDays:
          description: The expiry period of the API token in days.
          example: 30
          type: integer
        id:
          description: The API token's ID.
          example: clm8q7f6q000008lcgyougpsk
          type: string
        kind:
          description: The kind of the API token.
          enum:
            - STANDARD
            - DIRECT_ACCESS
          example: STANDARD
          type: string
        lastUsedAt:
          description: >-
            The time when the API token was last used in UTC, formatted as
            `YYYY-MM-DDTHH:MM:SSZ`.
          example: '2022-11-22T04:37:12Z'
          format: date-time
          type: string
        name:
          description: The name of the API token.
          example: My token
          type: string
        roles:
          description: The roles of the API token.
          items:
            $ref: '#/components/schemas/ApiTokenRole'
          type: array
        shortToken:
          description: The short value of the API token.
          example: short-token
          type: string
        startAt:
          description: >-
            The time when the API token will become valid in UTC, formatted as
            `YYYY-MM-DDTHH:MM:SSZ`.
          example: '2022-11-22T04:37:12Z'
          format: date-time
          type: string
        token:
          description: The value of the API token.
          example: token
          type: string
        type:
          description: The type of the API token.
          enum:
            - DEPLOYMENT
            - WORKSPACE
            - ORGANIZATION
          example: WORKSPACE
          type: string
        updatedAt:
          description: >-
            The time when the API token was last updated in UTC, formatted as
            `YYYY-MM-DDTHH:MM:SSZ`.
          example: '2022-11-22T04:37:12Z'
          format: date-time
          type: string
        updatedBy:
          $ref: '#/components/schemas/BasicSubjectProfile'
      required:
        - createdAt
        - description
        - id
        - kind
        - name
        - shortToken
        - startAt
        - type
        - updatedAt
      type: object
    Error:
      properties:
        message:
          type: string
        requestId:
          type: string
        statusCode:
          maximum: 600
          minimum: 400
          type: integer
      required:
        - message
        - requestId
        - statusCode
      type: object
    BasicSubjectProfile:
      properties:
        apiTokenName:
          description: >-
            The API token's name. Returned only when `SubjectType` is
            `SERVICEKEY`.
          example: my-token
          type: string
        avatarUrl:
          description: >-
            The URL for the user's profile image. Returned only when
            `SubjectType` is `USER`.
          example: https://avatar.url
          type: string
        fullName:
          description: The subject's full name. Returned only when `SubjectType` is `USER`.
          example: Jane Doe
          type: string
        id:
          description: The subject's ID.
          example: clm8qv74h000008mlf08scq7k
          type: string
        subjectType:
          description: The subject type.
          enum:
            - USER
            - SERVICEKEY
          example: USER
          type: string
        username:
          description: The subject's username. Returned only when `SubjectType` is `USER`.
          example: user1@company.com
          type: string
      required:
        - id
      type: object
    ApiTokenRole:
      properties:
        deploymentId:
          description: >-
            Required when EntityType is DAG or TAG. The deployment containing
            the DAG.
          example: clm8t5u4q000008jq4qoc3031
          type: string
        entityId:
          description: >-
            The ID of the entity. For DAG roles, this is the DAG ID. For TAG
            roles, this is the tag value.
          example: clm8sgvai000008l794psbkdv
          type: string
        entityType:
          description: The type of the entity.
          enum:
            - DEPLOYMENT
            - WORKSPACE
            - ORGANIZATION
            - DAG
            - DAG_TAG
          example: WORKSPACE
          type: string
        role:
          description: The role of the API token.
          example: WORKSPACE_MEMBER
          type: string
      required:
        - entityId
        - entityType
        - role
      type: object
  securitySchemes:
    JWT:
      scheme: bearer
      type: http

````