November 28, 2025 · API

📣 New Feature: Self-Generated Temporary Token (v3)

We’ve introduced Self-Generated Temporary Tokens (v3), a new way to create short-lived, encrypted API tokens directly on the client side using an existing parent token. These temporary tokens allow you to grant limited, time-bound access to Cincopa APIs without exposing your main API key.

Self-generated temporary token v3 announcement

✅ Key Capabilities

  • Generate temporary tokens locally without backend requests
  • Short-lived tokens with automatic expiry
  • Optional restrictions: asset (RID), gallery (FID), permissions, IP, or host
  • Encrypted payload derived from the parent token
  • Works offline and prevents exposure of the main API token

Use Cases

Temporary tokens are used in several Cincopa features that run directly on the frontend and require secure, time-limited access. These include:

  • Upload Iframe
  • Embed Editor
  • Upload/Record Widgets
  • Cincopa Library Manager
  • Providing temporary upload or view access inside your SaaS content system. For example, Cincopa CMS plugins for Shopify, Strapi, WordPress, or Moodle.

This addition provides a controlled way to grant limited API access for a specific purpose and time window, without exposing the main API key

For enterprise deployments that also need customer-controlled storage and streaming continuity, see Customer-Owned Cloud Backup. That update explains source-and-metadata backup and hosting-ready streaming separately from API token permissions.

Published December 3, 2025

NEXT STEP

Continue Exploring

Start with one product area, one documentation surface, one support library, one internal portal, or one embedded training flow. Get that collection working well, help viewers understand what is inside, then reuse the same gallery across adjacent destinations without duplicating the library.