One key per job, with only the access it needs.
Each integration, script and AI assistant gets its own token. Give it the scopes it needs and nothing more, set an expiry date, and revoke it in one click. Every call is logged against the token that made it.


API tokens, piece by piece.
Scoped, expiring keys for every script, app and AI assistant.
What teams use it for.
Your shop, your BI tool and your AI assistant each have their own key, so one can be cut off without touching the others.
Show who and what touched which record, with the token behind every change.
When someone leaves, their personal tokens stop with their account, while service tokens keep running.
Connected in four steps.
- 01
Go to Settings, then API tokens, and choose a personal or a service token.
- 02
Select the scopes and, if you want, an expiry date and the allowed IP addresses.
- 03
Copy the token once and keep it in your secret manager. It is never shown again.
- 04
Review the usage log and rotate tokens on a schedule.
Where API tokens shows up.
API tokens, answered.
Where is the token stored?
Dika Ops keeps only a hash of the token. If it is lost, revoke it and create a new one.
Can a token have more access than its owner?
No. A personal token never exceeds its owner's permissions, and a service token is limited to the scopes an admin grants.
Who can create tokens?
Only signed-in users with two-factor authentication and the right permission. The token itself is then used by machines.
What if a token leaks?
Revoke it and every call with it stops at once. The usage log shows what it was used for.
Run the whole company from one place.
Dika Ops is in closed beta. We onboard a few companies at a time and set everything up with you.