Every request to the Video API must carry a valid API token, and which token you use determines what you're allowed to do.
Bearer authentication
The API is protected against unauthorized access. Include your token in the Authorization header of every request, using the Bearer scheme:
Authorization: Bearer eyJhbGciOiJIUzI1****
Requests without a valid token receive 401 Unauthorized.
Token types
There are two types of API tokens with different scopes.
Instance API Token (full access)
Instance tokens are created by administrators and provide full access to all API resources — they can create, read, update, and delete every room in the tenant, and they are the only tokens accepted by the feedbacks endpoints. A room created with an Instance API Token belongs to no organization.
How to obtain one:
- Log in as an admin user into the MeetOne application.
- Navigate to the API Tokens section via the side menu, or directly at
https://acme.meetone.io/admin_ng/api_tokens. - Create a token, giving it a name and an expiry date.
- Copy the token from the details page.
Organization API Token (scoped access)
Organization tokens are designed for organizations to integrate with their own systems. They work against the same room endpoints as an Instance API Token, but every request is scoped to the organization the token belongs to:
- Create rooms — the room is owned by the token's organization.
- Read, update, close, and delete the organization's own rooms.
- Read signaling data for the organization's own rooms.
- List rooms belonging to the organization or to its doctors.
Rooms of other organizations are not visible to the token: they answer 404 Not Found, exactly as an unknown room token would — not 403 Forbidden.
The feedbacks endpoints are the exception. They are tenant-wide and require an Instance API Token.
Organization API Tokens are also rate limited: 20 requests per minute sustained, with bursts of up to 50 requests per minute. See Rate limits for guidance on staying within them.
How to obtain one:
- Log in as an organization owner.
- Navigate to the Integrations page.
- Your API token is displayed in the API section.
- Use the "Regenerate" button if you need a new token.
An administrator of the organization can also create additional tokens under Developer > API Tokens in the admin area.
What each token can do
| Capability | Instance API Token | Organization API Token |
|---|---|---|
List rooms (GET /api/rooms) |
Every room in the tenant | Rooms belonging to the organization or to its doctors |
Create a room (POST /api/rooms) |
Yes — the room belongs to no organization | Yes — the room is owned by the token's organization |
| Read, update, close, delete a room | Any room in the tenant | The organization's own rooms; others return 404 Not Found |
WebRTC signaling (GET /api/rooms/{room_token}/signaling) |
Any room in the tenant | The organization's own rooms; others return 404 Not Found |
Room feedbacks (/api/room_feedbacks, /api/room_feedbacks/summary) |
Yes | No — returns 403 Forbidden, requires Instance API Token |
| Rate limit | Not specified | 20 req/min sustained, bursts to 50 req/min |
401 responses
Any request missing a token, or presenting an invalid or expired one, receives 401 Unauthorized. See Errors & pagination for the full list of status codes returned by the API.
An Organization API Token asking for a room that belongs to another organization gets 404 Not Found, not 403 Forbidden. The API does not confirm that a room exists outside the token's scope, so treat 404 on a room you expected to see as a scope problem rather than a deleted room.
Security best practices
- Keep tokens server-side. Never embed an API token in browser JavaScript, a mobile app, or any other client the end user controls — send requests to the Video API from your backend only.
- Store tokens as secrets. Use environment variables or a secrets manager, not source control or configuration files checked into a repository.
- Set expiry dates on Instance API Tokens and re-create them periodically rather than using a single long-lived token indefinitely.
- Regenerate Organization API Tokens from the Integrations page if you suspect a token has been exposed.
- Prefer the narrowest token for the job. If your integration only manages your own organization's rooms, use an Organization API Token rather than an Instance API Token — it can create and manage them, and it cannot reach anything outside your organization.
An Instance API Token can create, read, update, and delete every room and feedback in your tenant. Handle it with the same care as an administrator credential.
Related
Questions? Contact us at support@meetone.io.