Configuration
API tokens
Generate scoped tokens per app — each app authenticates with its own key, rate limit and audit trail.
Active tokens
across 4 apps
API calls today
▲ 3.8% vs yesterday
Failed auths (24 h)
▲ mostly crm-legacy
Expiring ≤ 14 d
crm-legacy · Aug 30
| Token ▼ | App | Scopes | Rate limit | Created | Last used | Calls today | Status | ||
|---|---|---|---|---|---|---|---|---|---|
billing-prod mok_live_b7f2… |
BAbilling-app | send:mailread:messages | 2,000/min | 2026-05-02 | 12 s ago | 18,420 | Active | ||
newsletter-bulk mok_live_9d04… |
NLnewsletter | send:mail | 10,000/min | 2026-03-14 | 3 min ago | 52,880 | Active | ||
tools-alerts mok_live_51ce… |
ITinternal-tools | send:mailread:events | 500/min | 2026-06-21 | 41 s ago | 6,104 | Active | ||
etl-readonly mok_live_77ab… |
AEanalytics-etl | read:messagesread:events | 1,000/min | 2026-07-09 | 1 h ago | 6,716 | Active | ||
billing-staging mok_test_3c99… |
BAbilling-app | send:mail | 200/min | 2026-08-01 | 2 d ago | 0 | Idle | ||
crm-legacy mok_live_0f1e… |
NLnewsletter | send:mail | 100/min | 2025-11-30 | 26 d ago | 0 | Expiring |
Secrets are shown once at creation and stored as bcrypt hashes — only the prefix is ever visible again.
How apps authenticate
HTTP API and SMTP relay both accept per-app tokens.
# send mail via the HTTP API curl -X POST https://mailops.internal/api/v1/send \ -H "Authorization: Bearer mok_live_b7f2…" \ -H "Content-Type: application/json" \ -d '{"from":"billing@acme.com","to":"customer@example.org","subject":"Invoice #4821","template":"invoice"}' # or over SMTP — token as the password AUTH PLAIN user=billing-app pass=mok_live_b7f2…