Token calls require workflows-read, workspaces-read, and a workspace administrator as the token owner. The public-output-only ability does not grant access to this summary.
The summary includes origin, actor_user_id, actor_token_id, actor_token_name, trigger_auth_mode, metadata, parent_run_id and root_run_id. When the root record is available, detail responses also include root_workflow_id for cross-workflow navigation.
Actor fields identify the direct authenticated caller. Subworkflows have origin workflow, no authenticated direct caller, copied metadata, and links to the parent and initial run. Replays have origin replay, record their new caller, start a new execution tree, and retain context_data.source_run_id as the link to the replayed run.
Token names and historical identifiers survive deletion of the token. Historical runs have unknown origin/actor fields and empty metadata unless recorded previously. Their root ID falls back to their own run ID; legacy child lineage is not automatically backfilled.
Metadata is fixed at creation. This summary does not include exact run inputs or step outputs; use the existing input, steps and public-output endpoints for those fragments.