Configuration

API tokens

Generate scoped tokens per app — each app authenticates with its own key, rate limit and audit trail.

◔ Monitor app usage
Active tokens
across 4 apps
API calls today
▲ 3.8% vs yesterday
Failed auths (24 h)
▲ mostly crm-legacy
Expiring ≤ 14 d
crm-legacy · Aug 30
Token ▼AppScopesRate limit CreatedLast usedCalls todayStatus
billing-prod
mok_live_b7f2…
BAbilling-app send:mailread:messages 2,000/min 2026-05-02 12 s ago 18,420 Active
newsletter-bulk
mok_live_9d04…
NLnewsletter send:mail 10,000/min 2026-03-14 3 min ago 52,880 Active
tools-alerts
mok_live_51ce…
ITinternal-tools send:mailread:events 500/min 2026-06-21 41 s ago 6,104 Active
etl-readonly
mok_live_77ab…
AEanalytics-etl read:messagesread:events 1,000/min 2026-07-09 1 h ago 6,716 Active
billing-staging
mok_test_3c99…
BAbilling-app send:mail 200/min 2026-08-01 2 d ago 0 Idle
crm-legacy
mok_live_0f1e…
NLnewsletter send:mail 100/min 2025-11-30 26 d ago 0 Expiring
Secrets are shown once at creation and stored as bcrypt hashes — only the prefix is ever visible again.

How apps authenticate

HTTP API and SMTP relay both accept per-app tokens.

# send mail via the HTTP API
curl -X POST https://mailops.internal/api/v1/send \
  -H "Authorization: Bearer mok_live_b7f2…" \
  -H "Content-Type: application/json" \
  -d '{"from":"billing@acme.com","to":"customer@example.org","subject":"Invoice #4821","template":"invoice"}'

# or over SMTP — token as the password
AUTH PLAIN user=billing-app pass=mok_live_b7f2…