Skip to main content

API tokens

In a private chat with @UkiyoComputeBot, use /tokens to create or revoke a token. If your account has no email, enter it once during creation. Existing-email users are not asked again. Copy the secret when it is revealed. It cannot be recovered from the stored hash. Treat it like a password: do not paste it into support tickets, Git, public chats, agent transcripts, or screenshots. Supply it to clients as UKIYO_API_TOKEN using your local secret manager or private environment configuration. Do not put real tokens in shared examples. Revoke lost/exposed tokens immediately through /tokens. A revoked token must no longer authenticate.

Deployment credentials

The GPU-ready email and deployment access flow provide the actual SSH host, port, username, and key or password. API clients can use the audited credentials-reveal endpoint; keep its response out of logs. A Ukiyo API token is not an SSH password. A Jupyter authentication token is also separate.

Lost access

Create a replacement API token in private Telegram if needed. For a deployment, check its status and retrieve access details through the authenticated client. If that fails, contact support with the deployment ID, not the secret itself.