Skip to content
Odinex Cloud
Concepts

Projects and API tokens

How resources are grouped, who can access them, and how tools authenticate.

Organizations and projects

When you sign up you get a personal organization. The organization owns the prepaid balance, the limits, payments and monthly statements. Members of an organization have one of these roles: owner, admin, billing or member.

Resources (servers, volumes, networks, …) live in projects inside the organization. A project is a workspace: it groups resources, gives people access to them and holds the API tokens that automate them. Use separate projects to keep environments apart, for example production and staging. Your effective role in a project is admin, member or readonly.

A project can only be deleted when it contains no resources.

API tokens

Tools such as the odx CLI, the Terraform provider and your own scripts authenticate with a project API token:

  • A token belongs to exactly one project and only sees that project's resources.
  • Its scope is read (it can list and read, every change is refused with 403 forbidden) or read_write.
  • It can have an expiry date. The console shows when each token was last used.
  • The secret starts with odx_ and is shown once, when you create it. Store it in a password manager or secret store. Revoke tokens you no longer need; revoking takes effect immediately.

Create tokens in the console: Projects → your project → API tokens → Create API token. Tokens can only be created and revoked from a console session, not with another token.

Send the token as a bearer token:

curl -H "Authorization: Bearer $ODX_TOKEN" https://api.odinex.cloud/v1/servers

Anyone with a read_write token can create and delete resources in that project, which costs money. Never commit tokens to version control or paste them into tickets.

All tokens of a project share one rate limit budget.

The console session

The console uses the same API with a session cookie instead of a token. Endpoints for the account, projects, billing and support (marked Console session in the API reference) only work with a session.

On this page