Create a token
Open Profile settings → External API. Give the token a recognizable name, choose the permissions it needs, and set an expiration of 30, 90, or 365 days. Click Create token, then copy the secret into your secret manager. Hackrate shows the full token only once. You can have up to 10 active tokens and revoke one from the same page.
Send the token as a bearer credential:
/api/v1/admin. The API reference tab in these docs is generated from openapi/external-admin-v1.json. The platform OpenAPI document also lists endpoints, request bodies, and responses. A token scope never grants access beyond its owner’s current role. Role changes take effect immediately, and revocation stops the next request.
For report search, the API supports filters and cursor pagination. Pass nextCursor back unchanged with the same filters and sort order to fetch the next page.