> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gcore.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Credentials for applications

> Create a named token that an application can use, and delete it when that access should stop.

An application can make requests for the account without a person signing in on each request. The value is shown only once, at creation. After that, the list shows the name and the expiration date.

Navigate to **General** > **Security** > **API Tokens** and click **Create token**.

Enter a **Name**, optionally add a **Description**, and set **Expiration**. The date cannot be more than 365 days ahead.

<Frame>
  <img src="https://mintcdn.com/gcore/Nbp9NWcfeDrP4wS6/images/docs/reseller-support/security/api-tokens/api-tokens-image1.png?fit=max&auto=format&n=Nbp9NWcfeDrP4wS6&q=85&s=528a6d431169bb5d7518c9f5c05c0e6d" alt="Name, description, and expiration on the create form" width="564" height="364" data-path="images/docs/reseller-support/security/api-tokens/api-tokens-image1.png" />
</Frame>

Click **Create** and copy the token before closing the dialog. It cannot be viewed again. Click **OK, I've copied token** to return to the list.

<Frame>
  <img src="https://mintcdn.com/gcore/Nbp9NWcfeDrP4wS6/images/docs/reseller-support/security/api-tokens/api-tokens-image2.png?fit=max&auto=format&n=Nbp9NWcfeDrP4wS6&q=85&s=324a0ec6237f018fe15f9b620cf5d4c3" alt="New API token dialog with Copy and the token value" width="600" height="475" data-path="images/docs/reseller-support/security/api-tokens/api-tokens-image2.png" />
</Frame>

## Send a request

Put `APIKey` and the token in the `Authorization` header. A sign-in session uses `Bearer` in that header instead.

```http theme={null}
GET https://api.gcore.com/iam/clients
Authorization: APIKey <token>
```

The request returns the customer accounts. CDN, Cloud, FastEdge, WAAP, and Billing calls use this header too, and are grouped in [Reseller API](/reseller-support/api).

## Delete a token

In the token row, open **Actions** and select **Delete API token**, then confirm **Delete**. Applications that use the token lose access, and the deletion cannot be reversed. **Cancel** leaves the token in place.

<Frame>
  <img src="https://mintcdn.com/gcore/Nbp9NWcfeDrP4wS6/images/docs/reseller-support/security/api-tokens/api-tokens-image3.png?fit=max&auto=format&n=Nbp9NWcfeDrP4wS6&q=85&s=de4f9d9a8c30a4c9afcbb96e6744ba28" alt="Warning before deleting an API token" width="600" height="323" data-path="images/docs/reseller-support/security/api-tokens/api-tokens-image3.png" />
</Frame>
