List the authenticated user's access tokens
GET
/users/{username}/tokens
const url = 'https://gitea.example.com/api/v1/users/example/tokens';const options = {method: 'GET', headers: {Authorization: 'Basic <credentials>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://gitea.example.com/api/v1/users/example/tokens \ --header 'Authorization: Basic <credentials>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”username
required
string
Username of to user whose access tokens are to be listed
Query Parameters
Section titled “Query Parameters”page
integer
Page number of results to return (1-based)
limit
integer
Page size of results
Responses
Section titled “Responses”AccessTokenList represents a list of API access token.
Media typeapplication/json
Array<object>
AccessToken represents an API access token.object
created_at
The timestamp when the token was created
string format: date-time
id
The unique identifier of the access token
integer format: int64
last_used_at
The timestamp when the token was last used
string format: date-time
name
The name of the access token
string
scopes
The scopes granted to this access token
Array<string>
sha1
The SHA1 hash of the access token
string
token_last_eight
The last eight characters of the token
string
Examplegenerated
[ { "created_at": "2026-04-15T12:00:00Z", "id": 1, "last_used_at": "2026-04-15T12:00:00Z", "name": "example", "scopes": [ "example" ], "sha1": "example", "token_last_eight": "example" }]APIForbiddenError is a forbidden error response
Media typeapplication/json
Headers
Section titled “Headers”message
string
url
string