Token Storage
Token Storage for PanelConfig API consumers and operators.
API tokens should be stored like SSH keys or database passwords. Use environment variables, deployment secrets, or a secrets manager. Do not store them in PHP files, public configuration files, or JavaScript bundles.
Procedure
- Generate or identify the token in PCAdmin.
- Send a validation request to
/api/v1/me.php. - Confirm that the JSON envelope contains
success: true. - Move the token into the final secret storage location.
- Review request logs after the integration starts using the API.
Example
curl -i https://panel.example.com/api/v1/me.php \
-H "Authorization: Bearer pc_YOUR_TOKEN" \
-H "Accept: application/json"Troubleshooting
- Check that the web server forwards the
Authorizationheader to PHP. - Make sure the token starts with the copied
pc_value and has not been cut off. - Confirm the token has not expired.
- Confirm the user attached to the token is still active.
Audit Logging
Token creation calls the audit helper. Authenticated API requests update last_used_at and insert request records into api_requests when the table exists.