Skip to content
These docs describe staging.zkao.io and the @zksecurity/zkao-cli@next release. For production, see docs.zkao.io.

The calling token and its project

GET
/token
curl --request GET \
--url https://zkao.io/api/v1/token \
--header 'Authorization: Bearer <token>'

Any valid token may call this, whatever its scopes. Use it to learn which project (and organization) a token belongs to.

OK

Media typeapplication/json
object
id
required
string
name
required
string
scopes
required
Array<string>
repositoryIds
required

Repositories the token is restricted to. Empty means every repository of the project.

Array<string>
expiresAt
required
string | null format: date-time
spendLimitCredits
required

Credits this token may spend. Null means no limit.

integer | null
project
required
object
id
required
string
slug
required
string
name
required
string
organization
required

The organization a project belongs to. Credits are held and billed at this level and shared by every project in it.

object
id
required
string
slug
required

URL segment of the organization (/orgs/<slug>), unique across zkao.

string
name
required
string
Examplegenerated
{
"id": "example",
"name": "example",
"scopes": [
"example"
],
"repositoryIds": [
"example"
],
"expiresAt": "2026-04-15T12:00:00Z",
"spendLimitCredits": 1,
"project": {
"id": "example",
"slug": "example",
"name": "example",
"organization": {
"id": "example",
"slug": "example",
"name": "example"
}
}
}

Missing, malformed, expired, or revoked token

Media typeapplication/json
object
error
required
object
code
required
string
Allowed values: unauthorized forbidden not_found bad_request conflict insufficient_credits repository_initializing diff_base_required diff_base_not_allowed diff_base_invalid diff_empty rate_limited internal
message
required
string
Example
{
"error": {
"code": "unauthorized"
}
}