# Generate API token with fixed scope before launching server?

**URL:** https://discourse.jupyter.org/t/generate-api-token-with-fixed-scope-before-launching-server/24449
**Category:** JupyterHub
**Created:** [March 12, 2024, 11:52am UTC](https://discourse.jupyter.org/t/generate-api-token-with-fixed-scope-before-launching-server/24449 "2024-03-12T11:52:25Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Mehmet\_Tekman](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/mehmet_tekman/32/10844_2.png) [@Mehmet\_Tekman](https://discourse.jupyter.org/u/Mehmet_Tekman)
#### Post date: [March 12, 2024, 11:52am UTC](https://discourse.jupyter.org/t/generate-api-token-with-fixed-scope-before-launching-server/24449/1 "2024-03-12T11:52:25Z")

</div>

I have some Javascript charts that I display to the users on their spawn page, so they can see how busy the server is before they spawn.

The JS makes a fetch request to access a custom endpoint I made (`/hub/sysmon`) which requires a `read:users` scope-level token.

My current method of getting this token is to spawn the server, register a new token with that scope via the UI, copy the token, and then modify the JS that makes the fetch request to use that token.

I wish to do this more dynamically (i.e. define/generate a token with read:users scope beforehand, register it with JupyterHub, and use it within my JS).

I’ve seen [register api tokens via configuration](https://jupyterhub.readthedocs.io/en/stable/howto/rest.html#register-api-tokens-via-configuration) in the Docs.

I’ve seen that I can define `c.JupyterHub.services`, but the API tokens we generate here via openssl do not seem to have a scope, except for either admin or non-admin.

I’ve seen that I can define `c.JupyterHub.load_roles`, which _do_ define scopes, but don’t let you define an API token before hand.

Would I need to define both to make this work, e.g.:

```auto
c.JupyterHub.load_roles = [{
        "name": "getmetrics",
        "scopes": ["read:users"]
    }]
c.JupyterHub.services = [{
        'name': 'getmetrics',
        'api_token': <openssl key>
    }]

```

?

---

<div class="post-metadata">

### Author: ![minrk](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/minrk/32/13_2.png) [@minrk](https://discourse.jupyter.org/u/minrk)
#### Post date: [March 14, 2024, 2:51pm UTC](https://discourse.jupyter.org/t/generate-api-token-with-fixed-scope-before-launching-server/24449/2 "2024-03-14T14:51:40Z")

</div>

> [@Mehmet\_Tekman](#):
>
> Would I need to define both to make this work, e.g.:

Yes, a `role` is really a name for a bundle of scopes. Services can be _assigned_ to one or more roles. So the way to create a single token with specific scopes is just what you said, with one missing line: assign the service to the role:

```auto
c.JupyterHub.load_roles = [
    {
        "name": "getmetrics",
        "scopes": ["read:users"],
        "services": ["getmetrics"], # <--- this is where the service 'getmetrics' is assigned the role 'getmetrics'
    }
]
c.JupyterHub.services = [
    {
        "name": "getmetrics",
        "api_token": "<openssl key>",
    }
]

```

---

<div class="post-metadata">

### Author: ![Mehmet\_Tekman](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/mehmet_tekman/32/10844_2.png) [@Mehmet\_Tekman](https://discourse.jupyter.org/u/Mehmet_Tekman)
#### Post date: [March 14, 2024, 3:36pm UTC](https://discourse.jupyter.org/t/generate-api-token-with-fixed-scope-before-launching-server/24449/3 "2024-03-14T15:36:07Z")

</div>

Thank you, it works perfectly
