docs: runbook token listing reads the items envelope (sage)

Darkwing's correction, checked against the 2.7.0 OpenAPI: GET /tokens
returns PaginatedAPIToken, with items possibly null.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-08 17:17:18 -05:00
co-authored by Claude Opus 5.5
parent 67d29f7da5
commit 7780ef1e54
2 changed files with 6 additions and 1 deletions
+1 -1
View File
@@ -357,7 +357,7 @@ role. The stack never writes this file.
`svc -X DELETE "$VK/api/v2/tokens/<old id>"`. A revoke hits that one
token, and it gets 401 on its next request. `mint` printed the old
id. If you didn't keep it, list the bot's tokens as `svc-$BIZ`:
`svc "$VK/api/v2/tokens?owner_id=<bot id>" | jq -c '.[] | {id, title, expires_at}'`.
`svc "$VK/api/v2/tokens?owner_id=<bot id>" | jq -c '.items[]? | {id, title, expires_at}'`.
A plain `GET /tokens` lists only svc's own tokens, which is none, and
the owner's account gets 403 on the revoke. Then finish with section
4's `rm -f`, which deletes the header. The broker refuses to
+5
View File
@@ -1246,3 +1246,8 @@ which stay with him. Each item names who decided it and what happened.
names `GET /tokens?owner_id=<bot id>` as svc for finding an old
id. The async update lag has an upper bound of 5 s under load,
inside S3's 60 s overlap window (section U).
- Correction (Darkwing, same day): `GET /tokens` answers with the
paginated `{items, ...}` envelope (`PaginatedAPIToken` in the
2.7.0 OpenAPI), not a bare array. The probe's `items ?? body`
read hid it. The runbook's listing line now reads `.items[]?`,
which also covers a null `items`.