Skip to content

API Access Console Reference

Reference · Updated Jun 2026

Coming from another cloud?

▸AWS·IAM Console

This Quake AI feature maps to AWS’s IAM Console.

▸DigitalOcean·API Console

This Quake AI feature maps to DigitalOcean’s API Console.

▸Hetzner·API Token

API Tokens (project-scoped Bearer tokens)high

  • Hetzner API tokens are project-scoped: each token is valid only for the project it was created in and must be separately generated per project. OpenStack Keystone application credentials are user-scoped and can be used across projects when the user has appropriate roles.
  • Hetzner has no OAuth2/OIDC integration for API access; all programmatic access requires a static bearer token. Keystone supports OIDC federation, LDAP backends, and federated identity (SAML2).
  • Hetzner tokens have no built-in expiry and must be manually rotated; there is no token TTL or refresh concept. Keystone tokens have configurable TTLs (default 1 hour) and support re-authentication.
  • Hetzner tokens are either read-only or read-write with no fine-grained scope. OpenStack roles (admin, member, reader) provide service-level access control per project.
Hetzner docs ↗

API access console reference

The API section in the Quake AI console ({CONSOLE_REGION_URL}/papi/*) provides tools for managing programmatic access to your cloud project. It contains three pages (S3 Credentials, App Credentials, and API Endpoints) plus a Get Token action on the endpoints page.

S3 credentials#

Console path: API > S3 Credentials ({CONSOLE_REGION_URL}/papi/s3-credentials)

Manage EC2-compatible credentials for S3 object storage access. Unlike application credentials, S3 credentials are scoped to your user account, not a single project.

S3 Credentials console page showing one credential named test-upload-creds with inline copy icons in the Access Key and Secret Key column and a per-row settings menu with s3cmd config and DeleteClick to zoom
S3 Credentials page showing one credential with inline copy icons and a per-row settings menu
ColumnDescription
ID/NameCredential identifier and the name you assigned at creation
ProjectThe project the credential was created under
Access Key / Secret KeyThe access key shown in full and the masked secret key, each with a copy icon
ActionThe per-row settings menu

Actions: Create S3 Credential; per-row settings menu: s3cmd config, Delete; inline copy icons in the Access Key / Secret Key column

How-to: Create S3 credentials

Application credentials#

Console path: API > App Credentials ({CONSOLE_REGION_URL}/papi/application-credentials)

Create and manage application credentials for authenticating the OpenStack CLI, SDKs, and Terraform without your account password. Each credential is scoped to the current project.

Application Credentials console page showing the credential table with columns for ID/Name, Project, Description, Expires At, Unrestricted, and RolesClick to zoom
Application Credentials page showing the credential table columns
ColumnDescription
ID/NameCredential identifier and the name you assigned
ProjectThe project this credential is scoped to
DescriptionOptional description set during creation
Expires AtExpiration date, if set
UnrestrictedWhether the credential can manage trusts, other credentials, and Kubernetes clusters
RolesRoles assigned to this credential

Actions: Create Application Credential, Delete

How-to: Create application credentials

API endpoints#

Console path: API > API Endpoints ({CONSOLE_REGION_URL}/papi/endpoints)

View all service endpoint base URLs for your project. This page lists the same endpoints available through the Keystone service catalog, resolved for your region and project.

API Endpoints page showing all 12 service endpoint base URLs including Compute, Network, Volume, Image, Object Storage, and othersClick to zoom
API Endpoints page listing all 12 service base URLs with the Get Token button
Scrolled view of the API Endpoints page showing remaining service endpointsClick to zoom
API Endpoints page scrolled to show additional services

The endpoint table includes Compute (Nova), Network (Neutron), Block Storage (Cinder), Images (Glance), Object Storage (Swift/S3), Identity (Keystone), Orchestration (Heat), and Container Infrastructure (Magnum).

Reference: Service Endpoints: full endpoint table with clouds.yaml example and endpoint discovery details

Get token#

Console path: API > API Endpoints > Get Token button

Generate a project-scoped Keystone token directly from the console. The token authenticates direct HTTP requests to the service endpoints. Tokens are valid for 24 hours.

The Get Token button appears on the API Endpoints page. After selecting it, the console displays the token value with a copy action.

How-to: Get an API token

See also#

Was this page helpful?