1. Tokens
  2. Generate New Bearer Token
POST
/secrets
curl --request POST \
     --url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/secrets \
     --header 'Authorization: Bearer <token>' \
     --header 'Content-Type: application/json' \
     --data '{
  "secret_phrase": "<string>"
}'

Generate a new JWT bearer token for authenticating API requests. Bearer tokens provide secure access to all MasonHub API endpoints.

Tokens are encrypted and not stored in databases. They are decrypted and verified at request time for enhanced security.

​
Request Body

secret_phrase
required
string

Your secure secret phrase. This phrase is used to generate and later manage your tokens. Store it securely as you’ll need it to delete the token.

​
Secret Phrase Requirements

Your secret phrase should be:

  • Unique: Different from passwords or other credentials
  • Complex: Include multiple words, numbers, and special characters
  • Memorable: You’ll need it for token management operations
  • Secure: Not easily guessable or derivable

​
Example Secret Phrases

"Marketing Campaign 2024 - Secure Token #1!"
"Production API Access - Department Finance v2.1"
"Integration Testing Token - Project Phoenix @2024"
curl -X POST "https://app.masonhub.co/{account}/api/v1/secrets" \
  -H "Content-Type: application/json" \
  -d '{
    "secret_phrase": "My name is Inigo Montoya. As You WISH!!! You must have studied to be a greeper."
  }'
{
  "encrypted_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
}

​
Using Your Token

Once generated, include your bearer token in all API requests:

​
Authentication Header Format

Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

​
Complete API Request Example

curl -X GET "https://app.masonhub.co/{account}/api/v1/skus?limit=10" \
  -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \
  -H "Content-Type: application/json"

​
Environment-Specific Tokens

  • Sandbox

  • Production

Generate tokens for sandbox testing:

curl -X POST https://sandbox.masonhub.co/account/api/v1/secrets \
  -H "Content-Type: application/json" \
  -d '{"secret_phrase": "Sandbox Testing Token 2024"}'

Use different secret phrases for sandbox to keep environments separate.

​
Security Best Practices

​
Token Rotation Strategy

Implement regular token rotation for security:

1

Generate New Token

Create a new token with a different secret phrase

2

Update Applications

Deploy the new token to your applications

3

Test Functionality

Verify all integrations work with the new token

4

Delete Old Phrase

Use Delete Secret Phrase to invalidate the old token

​
Token Validation

Test your new token with a simple API call:

curl -X GET "https://app.masonhub.co/{account}/api/v1/skus?limit=1" \
  -H "Authorization: Bearer YOUR_TOKEN_HERE" \
  -H "Content-Type: application/json"

Store your secret phrase securely. You’ll need it to delete the token later. If you lose the secret phrase, you’ll need to contact support to revoke the token.

​
Common Errors