Model token
Passed via theAuthorization header. Keep it only in your server-side or trusted runtime environment; never put it in browser front-ends, mobile app bundles, or public repositories.
Profile access token
Used to query personal console data such as account balance. Example endpoint:/api/user/balance. See Balance API for more fields.
Query authorization token
Exposes read-only data-query capability to external systems. Keys start withqak-. The readable scope falls into three levels: current user / specified users / all users. See Query authorization.
Best practices
- Create separate tokens for different business systems for easier permission control and fault isolation.
- Store tokens in server-side environment variables or a secret manager.
- Record request IDs in production for troubleshooting (see Request ID).
- Disable or rotate a token immediately after it is leaked.