Skip to main content

Request authentication

Depending on the product or its resource, the following are used instead of a login and password to work with Selectel product APIs and authenticate requests:

  • IAM tokens — issued to service users and panel users. The token lifetime is 24 hours. IAM tokens are passed in the X-Auth-Token header and have different scopes:

  • static tokens (static_token) — issued to panel users and used to manage resources attached to the account. The token lifetime is unlimited. Static tokens are passed in the X-Token header.

The address (URL) for requests can be viewed in the Authentication subsection of the URL list instructions.

You can limit access to the API by addresses that include https://api.selectel.ru.

Account-scoped IAM token (X-Auth-Token)

The token is passed in the X-Auth-Token header.

An account-scoped IAM token (iam_token_account_scoped) provides access to managing most Selectel products and OpenStack API objects on par with the login and password in the my.selectel.ru control panel. It allows managing account resources.

Token lifetime is 24 hours.

The token allows managing:

Get an IAM token for an account

To authenticate in work tools, create a service user and obtain an account-scoped IAM token. To obtain a panel user's IAM token, use the Manage IAM tokens subsection of the Manage access keys instructions. We recommend using panel user IAM tokens only for testing.

To obtain an account-scoped IAM token, the user must have a permission where the scope Account is selected.

For your information

If you are using Windows, replace single quotes ('') with double quotes ("") in requests. We also recommend using PowerShell for requests and not using CMD.

  1. Send the following request:
curl -i -XPOST \
-H 'Content-Type: application/json' \
-d '{"auth":{"identity":{"methods":["password"],"password":{"user":{"name":"<username>","domain":{"name":"<account_id>"},"password":"<password>"}}},"scope":{"domain":{"name":"<account_id>"}}}}' \
'https://cloud.api.selcloud.ru/identity/v3/auth/tokens'

Specify:

  • <username> — service user name. You can view the name in the control panel: in the top menu, click IAM → Service Users section (the section is available only to the Account Owner and a user with the iam.admin role);
  • <account_id> — account number. You can view it in the control panel in the upper-right corner;
  • <password> — service user password, you can view it when creating the user or change to a new one.

Upon successful authorization, a response with code 201 Created will be returned in the following format:

HTTP/2 201
X-Subject-Token: token
  1. View the token in the X-Subject-Token header.

Project-scoped IAM token (X-Auth-Token)

The token is passed in the X-Auth-Token header.

A project-scoped IAM token (iam_token_project_scoped) provides access to managing most Selectel products and OpenStack API objects on par with the login and password in the my.selectel.ru control panel. It allows managing project resources.

Token lifetime is 24 hours.

The token allows managing:

Get an IAM token for a project

To authenticate in work tools, create a service user and obtain a project-scoped IAM token. To obtain a panel user's IAM token, use the Manage IAM tokens subsection of the Manage access keys instructions. We recommend using panel user IAM tokens only for testing.

To get an IAM token for a project, the user must have a permission where:

  • the scope Account is selected;
  • or the scope Projects is selected and the required project is selected.
For your information

If you are using Windows, replace single quotes ('') with double quotes ("") in requests. We also recommend using PowerShell for requests and not using CMD.

  1. Send the following request:
curl -i -XPOST \
-H 'Content-Type: application/json' \
-d '{"auth":{"identity":{"methods":["password"],"password":{"user":{"name":"<username>","domain":{"name":"<account_id>"},"password":"<password>"}}},"scope":{"project":{"name":"<project_name>","domain":{"name":"<account_id>"}}}}}' \
'https://cloud.api.selcloud.ru/identity/v3/auth/tokens'

Specify:

  • <username> — service user name. You can view the name in the control panel: in the top menu, click IAM → Service Users section (the section is available only to the Account Owner and a user with the iam.admin role);
  • <account_id> — account number. You can view it in the control panel in the upper-right corner;
  • <password> — service user password, you can view it when creating the user or change to a new one;
  • <project_name> — project name.

Upon successful authorization, a response with code 201 Created will be returned in the following format:

HTTP/2 201
X-Subject-Token: token
  1. View the token in the X-Subject-Token header.

Static token (X-Token)

For your information

An X-Token can only be issued to a panel user.

The token is passed in requests in the X-Token header.

A static token (static_token) provides full access to managing certain Selectel products on par with the login and password in the my.selectel.ru control panel. It does not allow managing OpenStack API objects.

The token lifespan is unlimited.

For APIs that do not support an account-scoped IAM token and a project-scoped IAM token, the static token is the only one:

Get a static token

  1. In the control panel, in the upper-right corner, open the menu (account number) and select Profile.
  2. Go to the Access section → API Keys tab.
  3. Click Add Key.
  4. Enter the key name.
  5. Click Add.

API token support

APIAccount-scoped IAM tokenProject-scoped IAM tokenStatic token
IAM✓✗✗
Federations✓✗✗
Balance✓✗✓
Statistics✓✗✓
Reports✗✗✓
Transactions✗✗✓
Dedicated servers✓✓✗
Cloud platform projects and resources✓✓✗
Project quotas and limits✓✓✗
Project quotas and limits✓✓✗
Direct public IP addresses of cloud servers✗✓✗
Private DNS✗✓✗
Managed Databases✗✓✗
Managed Kubernetes✗✓✗
Container Registry✗✓✗
Secrets✗✓✗
Certificates✗✓✗
Let’s Encrypt® certificates✗✓✗
Swift✗✓✗
Object Storage✗✓✗
Global router✓✗✗
CDN✗✓✗
DNS hosting (actual)✗✓✗
DNS hosting (legacy)✓✗✓
Selectel email service✗✓✗
IP address management service✗✗✓
Audit logs✓✗✗
Ready-made 1C cloud✗✓✗
Mobile Farm✓✓✗
Tickets✗✗✓
Attachments✗✗✓