ms_<prefix>_<secret>. The plaintext token is returned once,
so store the token immediately.
role_id is optional and defaults to the organization’s default API-token role. The selected role
cannot grant permissions the caller does not have. Omit expires_in_days for a non-expiring token;
explicit values are clamped to 1–1825 days. Creating tokens requires api_tokens.manage.