This article is for API providers. It covers the tokens that let a script or an agent act on your listings — publishing an OpenAPI document, editing endpoints, reading analytics — without your login.The Management API is the same REST the API Studio uses. A management token stands in for your session on those routes, and nothing else changes: the same validation, the same ownership checks, the same audit trail.
Management tokens are not API keys
Give each script or agent its own token with only the scopes it needs, set an expiry, and revoke it when the job is done. Tokens are created in Studio → Management API; the token itself is shown once.
Scopes
Deleting an API is never available to a token; do that in the Studio.
Calling it
Thejojapi CLI wraps these routes in commands with previews and confirmations. To call the routes directly, send the token as a bearer token to the Studio’s REST routes under https://app.jojapi.com/rest/:
Authorization, the header X-Management-Token: jm_… is accepted too.
Answers are JSON with a status field; the HTTP status is 200 for every answer the application produced, so read status, not the code:
Routes
Every route takes and returns JSON.GET routes take their parameters in the query string; POST routes take a JSON body. slug is the listing’s slug — the last part of its Studio URL.
Listings
Imports — publishing an OpenAPI document
The fastest way to keep a listing in step with your code is to publish its OpenAPI document. An import never touches an existing endpoint’s blocked/hidden flags, its group or its plans unless you ask it to.bundle is a JSON string in the import engine’s source-agnostic shape:
value_type is one of string, enum, number, integer, boolean, date, time, object, array, geopoint. Preview first, read the diff, then apply.
Pricing
create-api-plan answers the new plan as plan: {slug, type, blocked}. A public plan must fit the pricing page: at most 10 public plans per API, one of them pay-as-you-go. This applies both when you create a plan as public and when update-api-plan makes a private plan public; over the limit the status is public_plans_limit_reached. studio/grant-quota takes the subscription.id that ProviderSubscriptions returns and an object_id from that subscription’s current_period.objects.
Analytics and subscribers
Subscriptions and plan transfers are identified by opaque string ids (
subscription.id, pending_transfer.id). Send them back exactly as you received them; they are not row numbers.
Worker code (edge gateway)
Every save is a preview unless it sends
production: true, and returns deploy: deployed with the new deployment (id, number, url) and whether it was promoted, or error with the build message. deploy.pending (also in provider-api-edge and provider-api-edge-deployments) lists what production does not run yet: changes ([{type: mode | template | file | variable | resource, name, change: added | changed | removed}]), production ({id, number}) and deployment, the latest preview ({id, number, status, error, url, current}; current: false means no deployment holds the saved changes yet). preview: true is still accepted and changes nothing. See Deployments and Worker code.
