You can create an API token manually in your browser and take a look in the network tab. There seems to be a REST API to get, create and delete API tokens.
However, I'm not sure whether the respective endpoints accept an API token as authorisation method. Just give it a try.