- Tokens
- Generate New Bearer Token
Tokens
Generate New Bearer Token
Generate a new JWT bearer token using a secret phrase
curl --request POST \
--url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
"secret_phrase": "<string>"
}'Generate a new JWT bearer token for authenticating API requests. Bearer tokens provide secure access to all MasonHub API endpoints.
Tokens are encrypted and not stored in databases. They are decrypted and verified at request time for enhanced security.
Request Body
Your secure secret phrase. This phrase is used to generate and later manage your tokens. Store it securely as you’ll need it to delete the token.
Secret Phrase Requirements
Your secret phrase should be:
- Unique: Different from passwords or other credentials
- Complex: Include multiple words, numbers, and special characters
- Memorable: You’ll need it for token management operations
- Secure: Not easily guessable or derivable
Example Secret Phrases
"Marketing Campaign 2024 - Secure Token #1!"
"Production API Access - Department Finance v2.1"
"Integration Testing Token - Project Phoenix @2024"
curl -X POST "https://app.masonhub.co/{account}/api/v1/secrets" \
-H "Content-Type: application/json" \
-d '{
"secret_phrase": "My name is Inigo Montoya. As You WISH!!! You must have studied to be a greeper."
}'
{
"encrypted_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}
Using Your Token
Once generated, include your bearer token in all API requests:
Authentication Header Format
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
Complete API Request Example
curl -X GET "https://app.masonhub.co/{account}/api/v1/skus?limit=10" \
-H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \
-H "Content-Type: application/json"
Environment-Specific Tokens
Sandbox
Production
Generate tokens for sandbox testing:
curl -X POST https://sandbox.masonhub.co/account/api/v1/secrets \
-H "Content-Type: application/json" \
-d '{"secret_phrase": "Sandbox Testing Token 2024"}'
Use different secret phrases for sandbox to keep environments separate.
Security Best Practices
Environment Variables
Store tokens in environment variables, never in source code
Secure Vaults
Use credential management systems like AWS Secrets Manager or HashiCorp Vault
Token Rotation
Regularly rotate tokens by generating new ones and deleting old secret phrases
Environment Separation
Use different tokens for sandbox and production environments
Token Rotation Strategy
Implement regular token rotation for security:
Generate New Token
Create a new token with a different secret phrase
Update Applications
Deploy the new token to your applications
Test Functionality
Verify all integrations work with the new token
Delete Old Phrase
Use Delete Secret Phrase to invalidate the old token
Token Validation
Test your new token with a simple API call:
curl -X GET "https://app.masonhub.co/{account}/api/v1/skus?limit=1" \
-H "Authorization: Bearer YOUR_TOKEN_HERE" \
-H "Content-Type: application/json"
Store your secret phrase securely. You’ll need it to delete the token later. If you lose the secret phrase, you’ll need to contact support to revoke the token.
Common Errors
curl -X POST "https://app.masonhub.co/{account}/api/v1/secrets" \
-H "Content-Type: application/json" \
-d '{
"secret_phrase": "My name is Inigo Montoya. As You WISH!!! You must have studied to be a greeper."
}'
curl --request POST \
--url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
"secret_phrase": "<string>"
}'{
"encrypted_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}