Skip to main content
The root HOOKFISH_API_KEY can access every resource. Give applications named, expiring broker tokens instead.

Exact paths and namespaces

Plain paths are exact. Hookfish does not silently turn them into folders. Append /** when you intend to grant descendants. Paths are canonical slash-delimited identifiers up to 768 characters.

Mint a token

The bearer value is returned once. A scoped token may delegate only equal or narrower scopes, under its dot-delimited token-name namespace, with an equal or earlier expiration. Hookfish records each delegation as a child grant. Use the token on access:
The same token cannot access user/personal/gmail/mcp. Grant user/personal/** only if the service needs that subtree. For a multi-tenant application, begin every connection and secret path with a tenant prefix such as organizations/acme. Mint tokens against that same prefix so a credential for one tenant cannot address another tenant’s paths. Revoke a name with DELETE /api/admin/tokens/{name}. This revokes the named token, every token delegated from it, and all deeper descendants. Unrelated token grant trees remain active. Rotating the root key invalidates all scoped tokens because it signs them.