Request authentication
Depending on the product or its resource, the following are used instead of a login and password to work with Selectel product APIs and authenticate requests:
-
IAM tokens — issued to service users and panel users. The token lifetime is 24 hours. IAM tokens are passed in the
X-Auth-Tokenheader and have different scopes:- Account-scoped IAM tokens (
iam_token_account_scoped) — for managing resources attached to the account; - Project-scoped IAM tokens (
iam_token_project_scoped) — for managing resources attached to the project;
- Account-scoped IAM tokens (
-
static tokens (
static_token) — issued to panel users and used to manage resources attached to the account. The token lifetime is unlimited. Static tokens are passed in theX-Tokenheader.
The address (URL) for requests can be viewed in the Authentication subsection of the URL list instructions.
You can limit access to the API by addresses that include https://api.selectel.ru.
Account-scoped IAM token (X-Auth-Token)
The token is passed in the X-Auth-Token header.
An account-scoped IAM token (iam_token_account_scoped) provides access to managing most Selectel products and OpenStack API objects on par with the login and password in the my.selectel.ru control panel. It allows managing account resources.
Token lifetime is 24 hours.
The token allows managing:
- users and roles (IAM) and federations;
- balance and consumption statistics;
- dedicated servers;
- OpenStack API objects (cloud servers, network disks, and others) using the API cloud platform projects and resources, project quotas and limits, for more details see the OpenStack documentation;
- global router ;
- DNS hosting (legacy);
- mobile farm.
Get an IAM token for an account
To authenticate in work tools, create a service user and obtain an account-scoped IAM token. To obtain a panel user's IAM token, use the Manage IAM tokens subsection of the Manage access keys instructions. We recommend using panel user IAM tokens only for testing.
To obtain an account-scoped IAM token, the user must have a permission where the scope Account is selected.
If you are using Windows, replace single quotes ('') with double quotes ("") in requests. We also recommend using PowerShell for requests and not using CMD.
- Send the following request:
curl -i -XPOST \
-H 'Content-Type: application/json' \
-d '{"auth":{"identity":{"methods":["password"],"password":{"user":{"name":"<username>","domain":{"name":"<account_id>"},"password":"<password>"}}},"scope":{"domain":{"name":"<account_id>"}}}}' \
'https://cloud.api.selcloud.ru/identity/v3/auth/tokens'
Specify:
<username>— service user name. You can view the name in the control panel: in the top menu, click IAM → Service Users section (the section is available only to the Account Owner and a user with theiam.adminrole);<account_id>— account number. You can view it in the control panel in the upper-right corner;<password>— service user password, you can view it when creating the user or change to a new one.
Upon successful authorization, a response with code 201 Created will be returned in the following format:
HTTP/2 201
X-Subject-Token: token
- View the token in the
X-Subject-Tokenheader.
Project-scoped IAM token (X-Auth-Token)
The token is passed in the X-Auth-Token header.
A project-scoped IAM token (iam_token_project_scoped) provides access to managing most Selectel products and OpenStack API objects on par with the login and password in the my.selectel.ru control panel. It allows managing project resources.
Token lifetime is 24 hours.
The token allows managing:
- dedicated servers;
- OpenStack API objects (cloud servers, network disks, and others) using the API cloud platform projects and resources, project quotas and limits, for more details see the OpenStack documentation;
- cloud platform — direct public IP addresses, private DNS, Managed Databases, Managed Kubernetes, Container Registry, secrets manager (secrets, certificates , Let’s Encrypt® certificates );
- S3 (Swift API and Object Storage API);
- DNS hosting;
- Selectel email service;
- ready-made 1C cloud;
- audit logs.
Get an IAM token for a project
To authenticate in work tools, create a service user and obtain a project-scoped IAM token. To obtain a panel user's IAM token, use the Manage IAM tokens subsection of the Manage access keys instructions. We recommend using panel user IAM tokens only for testing.
To get an IAM token for a project, the user must have a permission where:
- the scope Account is selected;
- or the scope Projects is selected and the required project is selected.
If you are using Windows, replace single quotes ('') with double quotes ("") in requests. We also recommend using PowerShell for requests and not using CMD.
- Send the following request:
curl -i -XPOST \
-H 'Content-Type: application/json' \
-d '{"auth":{"identity":{"methods":["password"],"password":{"user":{"name":"<username>","domain":{"name":"<account_id>"},"password":"<password>"}}},"scope":{"project":{"name":"<project_name>","domain":{"name":"<account_id>"}}}}}' \
'https://cloud.api.selcloud.ru/identity/v3/auth/tokens'
Specify:
<username>— service user name. You can view the name in the control panel: in the top menu, click IAM → Service Users section (the section is available only to the Account Owner and a user with theiam.adminrole);<account_id>— account number. You can view it in the control panel in the upper-right corner;<password>— service user password, you can view it when creating the user or change to a new one;<project_name>— project name.
Upon successful authorization, a response with code 201 Created will be returned in the following format:
HTTP/2 201
X-Subject-Token: token
- View the token in the
X-Subject-Tokenheader.
Static token (X-Token)
An X-Token can only be issued to a panel user.
The token is passed in requests in the X-Token header.
A static token (static_token) provides full access to managing certain Selectel products on par with the login and password in the my.selectel.ru control panel. It does not allow managing OpenStack API objects.
The token lifespan is unlimited.
For APIs that do not support an account-scoped IAM token and a project-scoped IAM token, the static token is the only one:
Get a static token
- In the control panel, in the upper-right corner, open the menu (account number) and select Profile.
- Go to the Access section → API Keys tab.
- Click Add Key.
- Enter the key name.
- Click Add.