API features and best practices for API token rotation #1891
Answered
by
JohnVillalovos
dazza-codes
asked this question in
Q&A
|
What are the best practices for using the gitlab-API (i.e. python-gitlab project) to rotate API tokens? (By rotate API tokens, I mean create/delete/recreate and capture the API token value via the gitlab-API.) Can a user effectively read/rotate their own API token using the gitlab API token? Can an owner of a project use the gitlab API to read/rotate project API tokens? Can an admin of a group use the gitlab API to read/rotate group API tokens (and can those group API tokens access any projects in the group)? Where is the RBAC documentation on gitlab-API and various types of API tokens (user, project, group with token-scope details)? |
Answered by
JohnVillalovos
Feb 15, 2022
Replies: 1 comment 1 reply
|
Quick comment from my phone. The source of truth for the API is https://docs.gitlab.com/ee/api/ |
1 reply
Answer selected by
nejch
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Quick comment from my phone. The source of truth for the API is https://docs.gitlab.com/ee/api/