Open Morse

Reference

Tokens

3 routes, generated from Morse’s own OpenAPI document. Every path below hangs off the base URL, and every one needs the bearer header.

The examples are built from each route’s schema, so the shapes and types are exactly what the API declares. The values are illustrative, and no one has run them.

Your tokens that haven't been revoked, newest first.

GET/users/me/tokens

Never the tokens themselves.

GET/users/me/tokens

curl "$MORSE/users/me/tokens" \
  -H "Authorization: Bearer $MORSE_TOKEN"
200
[
  {
    "created_at": "2026-10-02T10:30:00+05:30",
    "expires_at": "2026-10-02T10:30:00+05:30",
    "id": "3f9c1a24-5e6f-4b31-9a77-1b2c3d4e5f60",
    "last_four": "…",
    "last_used_at": "2026-10-02T10:30:00+05:30",
    "name": "Priya Shah",
    "status": "active"
  }
]

Make a token that acts as you everywhere in Morse.

POST/users/me/tokens

The whole token is in this response only: Morse keeps its fingerprint and can't show it again.

POST/users/me/tokens

curl -X POST "$MORSE/users/me/tokens" \
  -H "Authorization: Bearer $MORSE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "expires_at": "2026-10-02T10:30:00+05:30", "name": "Priya Shah" }'
201
{
  "created_at": "2026-10-02T10:30:00+05:30",
  "expires_at": "2026-10-02T10:30:00+05:30",
  "id": "3f9c1a24-5e6f-4b31-9a77-1b2c3d4e5f60",
  "last_four": "…",
  "last_used_at": "2026-10-02T10:30:00+05:30",
  "name": "Priya Shah",
  "status": "active",
  "token": "mp_YOUR_MORSE_TOKEN"
}

Stop one of your tokens working, from its next request.

DELETE/users/me/tokens/{token_id}

Revoking it again is harmless.

DELETE/users/me/tokens/{token_id}

curl -X DELETE "$MORSE/users/me/tokens/3f9c1a24-5e6f-4b31-9a77-1b2c3d4e5f60" \
  -H "Authorization: Bearer $MORSE_TOKEN"