openapi: 3.2.0 info: title: Ory Network Billing Project Tokens API description: 'Ory is open-source identity and access infrastructure, delivered as the Ory Network managed cloud. This document models the primary public and admin REST surfaces of an Ory Network project and the Ory Network Console (control plane). Two base URLs are in play. Project data-plane endpoints - Ory Kratos (identities, sessions, self-service flows), Ory Hydra (OAuth2 / OIDC), Ory Keto (permissions and relationship tuples), and courier messages - are served on the project-scoped host https://{project-slug}.projects.oryapis.com. The Ory Network Console API (workspaces, projects, project tokens, event streams, subscriptions) is served on https://api.console.ory.sh. Public self-service and OAuth2/OIDC endpoints are unauthenticated or use the end-user session; admin, Keto write, courier, and Console endpoints require an Ory API key / project or workspace API token passed as a Bearer token. Ory SDKs are auto-generated from these OpenAPI specifications. Endpoint set is representative and grounded in Ory''s published specs; consult the live reference for the exhaustive parameter and schema detail.' version: '1.0' contact: name: Ory url: https://www.ory.com license: name: Apache-2.0 url: https://github.com/ory/kratos/blob/master/LICENSE servers: - url: https://{project-slug}.projects.oryapis.com description: Ory Network project (Kratos, Hydra, Keto, Courier) variables: project-slug: default: your-project-slug description: The slug of your Ory Network project. - url: https://api.console.ory.sh description: Ory Network Console API (control plane) security: - oryApiKey: [] tags: - name: Project Tokens description: Ory Network project API token management. paths: /projects/{projectId}/tokens: parameters: - name: projectId in: path required: true schema: type: string format: uuid get: operationId: listProjectApiKeys tags: - Project Tokens summary: List project API tokens servers: - url: https://api.console.ory.sh responses: '200': description: The project's API tokens. content: application/json: schema: type: array items: $ref: '#/components/schemas/ProjectApiKey' post: operationId: createProjectApiKey tags: - Project Tokens summary: Create a project API token servers: - url: https://api.console.ory.sh requestBody: required: true content: application/json: schema: type: object properties: name: type: string responses: '201': description: The created token (value shown once). content: application/json: schema: $ref: '#/components/schemas/ProjectApiKey' /projects/{projectId}/tokens/{tokenId}: delete: operationId: deleteProjectApiKey tags: - Project Tokens summary: Delete a project API token servers: - url: https://api.console.ory.sh parameters: - name: projectId in: path required: true schema: type: string format: uuid - name: tokenId in: path required: true schema: type: string format: uuid responses: '204': description: Token deleted. components: schemas: ProjectApiKey: type: object properties: id: type: string format: uuid name: type: string value: type: string created_at: type: string format: date-time securitySchemes: oryApiKey: type: http scheme: bearer description: 'Ory API key. Project admin endpoints use an Ory project API key (ory_pat_...); Console endpoints use a workspace API key (ory_wak_...). Passed as `Authorization: Bearer `.'