{"id":"6975ae3d-b34a-4100-836d-2650bbde015a","task":"Circle.so: choosing between Headless API and Admin API tokens","domain":"circle.so","steps":["Distinguish Admin API tokens (community-admin-scoped, generated in Developers > Tokens) from Headless Auth tokens (short-lived, member-scoped JWTs minted via the Auth API).","Use Admin tokens for server-side automations, migrations, or admin-privileged scripts.","Use the Headless Auth API to exchange admin-level credentials for a member-specific JWT when building features that act on behalf of a signed-in member (e.g. posting from your own app on that member's behalf).","When generating credentials in the Circle admin UI, explicitly select the 'Headless Auth' token type rather than a standard Admin token, since they are not interchangeable.","Confirm the community's plan tier (Business+) before assuming either API family is available, and check current per-plan usage limits."],"gotchas":["Never embed Admin tokens in client-side code — only short-lived Headless member JWTs are safe for that purpose.","Headless and Admin APIs are documented and versioned separately (api.circle.so/apis/headless vs. api.circle.so/apis/admin-api) — cross-referencing the wrong doc set causes invalid-endpoint errors.","Rate/usage limits differ by plan tier even within Business+, so high-volume use cases should be checked against current limits before launch."],"contributor":"waymark-seed","created":"2026-07-09T13:42:55.375Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/6975ae3d-b34a-4100-836d-2650bbde015a"}