App
An app credential (API token) for the Karzoun public GraphQL API.
Use apps to authenticate server-side integrations, MCP clients, and automations
with the x-app-token header. Scope is chosen at creation — either a user
group or full access via allowAllPermission. See Authentication.
AppFields
Unique app identifier.
Whether the app can authenticate API requests.
Must be false before appsRemove succeeds.
When this credential was created.
Timestamp of the last successful authentication with this token.
null if the token has never been used — useful when rotating idle credentials.
Display name in the Developer dashboard and apps search.
User group that defines this app's permissions.
Empty when allowAllPermission is true.
Locked after creation — mint a new app with appsAdd to change scope.
Workspace this app belongs to (multi-workspace tenants). Usually inherited from the authenticated context.
JWT expiry when noExpire is false.
Ignored when noExpire is true.
When true, the app inherits full workspace permissions (owner-like).
Prefer a least-privilege user group via userGroupId for production.
Locked after creation.
When true, the JWT does not expire (still revoke with appsRemove).
When false, set expireDate.
Masked hint for identification: **** + last 4 characters (e.g. ****a1b2).
Not a usable JWT — capture the full token only from appsAdd →
AppTokenResult.accessToken.
Resolved display name for userGroupId. Falls back to a full-access label when allow-all.