Token

The panel has no login and no session. Every /api/v1 route authenticates on the X-Api-Key header alone, so the token is pasted here and kept in this browser's local storage. Nothing on the server side remembers it.

API token

The first one is printed once in the panel's log at startup on an empty database: look for “created the first admin token”.

Scopes decide what it can do: admin for nodes and rooms, users for subscribers, read for looking. The panel does not tell a caller which scopes its token holds, so the only way to find out is to try.
Used to build subscription links. The API returns a path (/sub/<token>) and never a URL, because it does not know how clients reach it. Defaulting to this page’s own origin.

Where the token goes

This UI runs as its own process and forwards /api/v1, /sub, /healthz, /openapi.json and /docs to the panel named by DRAKE_PANEL_URL. The forwarding is transparent: the token is attached in the browser and passed through unread, and this process stores none of its own.

Anyone with access to this browser profile has the token. Revoking it means deleting the API token in the panel's database; there is no route for that yet.