Create and protect a token
Create or revoke a personal access token in the signed-in API & CLI dashboard area. Tokens are required for the public API and CLI, and authenticated users can use them to create and deploy Free Boxes.
Treat a token like a password. Store it in a secret manager or CI secret, never in source control, browser code, screenshots, or a public ZIP.
- Open API & CLI in the Dashboard.
- Create a token with only the access you need.
- Use it in an Authorization Bearer header or through the CLI login command.
- Revoke it from the Dashboard when it is no longer needed.
Use the CLI
The CLI accepts exactly one readable .zip file. It can list Boxes, start an asynchronous deployment, inspect an import, and optionally wait for the import to finish.
Tips and limits
- For CI, set HTMBOX_TOKEN in the CI secret store. It takes precedence over stored CLI credentials and is not written to the CLI config file.
- Use --json for machine-readable CLI output.
- Use --wait when an automation step needs the completed hosted URL before continuing.
htmbox deploy ./site.zip --wait
HTMBOX_TOKEN=... htmbox boxes list --json
Know the boundaries
Tips and limits
- The CLI does not accept directories, zip folders, watch or synchronize files, edit Live Workspace files, activate Releases, or make billing changes.
- API ZIP imports accept one public ZIP URL or one multipart local ZIP. They are asynchronous and should be polled until a terminal status.
- The API base URL is https://htmbox.com/api/v1. Consult the API reference for endpoint payloads and error envelopes.