Skip to content
Contents

Guides

Authentication and tokens

Get your Nipto API token, send it with each call, and regenerate or revoke it.

Get your token

  1. Open the Nipto app and go to Settings, then Integrations, then Smart home.
  2. Tap Show my token. The button is active once your tribe has Premium.
  3. Copy the token and keep it somewhere safe, like the secrets.yaml of Home Assistant.

Each member has their own token. Showing it again gives back the same token, until it is regenerated or revoked.

Send it with each call

Put the token in the Authorization header, as is or after Bearer:

Authorization: YOUR_TOKEN
Authorization: Bearer YOUR_TOKEN

A call without a valid token answers 401 with the code UNAUTHENTICATED (see Errors). Only the schema itself can be read without a token, so tools can show the available fields.

Who the token acts as

  • The token acts as you, in the tribe you are in right now. If you change tribe, the token reads and writes the new one. If you leave your tribe, it stops working.
  • Your role applies. If you are under parental control, the activities you log wait for an admin to approve them, as in the app.
  • Anyone holding the token can read the data of your tribe and log activities: keep it secret.

Regenerate or revoke a token

On the same Smart home page, tribe admins can:

  • Regenerate: the old token stops working right away and a new one replaces it. Paste the new token everywhere you used the old one. The count of calls of the day carries over.
  • Revoke: the token stops working right away. Tap Show my token later to get a new one.