Overview
Tokens
Section titled “Tokens”The caller’s own nsin_live_ machine credentials — list, mint once, revoke — not his clients’ accounts and not the customer-panel API keys documented in openapi.yaml. All three refuse a machine token and require a dashboard session JWT, so a leaked token can neither mint a quieter replacement nor revoke the credential you would use to lock it out.