Access tokens
Personal access tokens let a script or agent act as you, with less power than your app sign-in.
Create a token
In the app: More → Developer access.
- Give the token a name you will recognise later ("Home Assistant", "Claude").
- Pick a scope:
- Read only: look up family data.
- Read and write: also create, change and delete family data.
- Pick which families: this family only (recommended) or all my families.
- Pick an expiry: 30, 90 or 365 days, or none.
- Copy the token. It is shown once. Fellesly keeps only a SHA-256 hash, so a lost token cannot be shown again; create a new one.
Tokens start with fly_. The list shows each token's first characters, scope, expiry and when it was last used. You can have up to 20.
Use a token
sh
curl -H "Authorization: Bearer $FELLESLY_TOKEN" https://api.fellesly.no/v1/meRevoke a token
Tap Revoke next to it. It stops working immediately. Tokens are also removed when your account is deleted or suspended, and stop working when they expire or when you leave the family they are bound to.
Keep tokens safe
- Treat a token like a password. Store it in a secret manager or environment variable, never in source code.
- Give each integration its own token, with the smallest scope and one family, so you can revoke one without breaking the others.
- A write token can delete family data that your role allows. Prefer read-only for dashboards and agents that only answer questions.
- Tokens cannot manage tokens, change your account, sign in, export or delete your account, or administer the family. Those need the app.
Managing tokens over HTTP
The app uses these endpoints with its own sign-in session. Access tokens get 403 here.
| Method | Path | Body |
|---|---|---|
GET | /v1/me/api-tokens | |
POST | /v1/me/api-tokens | { name, scope: "read" | "write", familyId?, expiresInDays? } |
DELETE | /v1/me/api-tokens/{id} |