Connect and organize

Permissions and tokens

Choose workspace scopes, create a machine token, and replace or revoke access.

Two checks apply to a scoped token: its explicit module permissions and its actor's current authority in the workspace. Adding a permission cannot exceed that actor's role or the issuer's grants. Secrets permissions apply across all environments in the token's one workspace.

Choose Secrets permissions

Permission Scope Allows Eligible actor roles
Read metadata secrets:read Status, types, environments, secret lists, history, audit activity and metadata comparison Owner, admin, member, guest
Manage secrets:edit Enable Secrets, manage environments, create/update/delete/import secrets and save changes Owner, admin
Read secret values secrets:values Reveal a current or historical value and export an environment Owner, admin

Select permissions explicitly. Manage does not automatically include Read metadata or Read secret values. Value comparison requires secrets:read and secrets:values. Rollback requires secrets:edit and secrets:values.

Metadata can contain display values: certificate, publishable and config values are unmasked, and connection strings are partly masked. Do not treat metadata access as a promise that no value can be seen. Management access can change a value's type, including its display behavior.

Create a token

  1. Sign in as a human owner/admin and select the intended workspace.
  2. Open Settings → API tokens and choose Create API token.
  3. Enter a name identifying the client, such as docs-demo-laptop.
  4. Choose Acts as: yourself or an eligible agent in this workspace. The default is your own actor. Another person's identity cannot be selected.
  5. Select only the required module permissions and an expiry. The default is 30 days; the maximum is 365 days. The API accepts a minimum of 60 seconds.
  6. Create the token and save it immediately in the client credential manager. It is shown once. Closing the panel loses that disclosure.

A token's ID is safe to use to identify it in an access request; its bearer value is a credential. List and self-inspection endpoints return metadata, not that bearer value.

Live authority and expiry

Personal tokens remain tied to live membership grants and identity status. Agent tokens remain tied to their active actor and role. Removing access, disabling an identity, expiring or revoking a credential can cause requests that once worked to be refused.

A scoped token can call only explicitly permitted API routes. It cannot issue tokens or use the human-only management and skill-download endpoints. Identity-provider sign-in credentials are not interchangeable with these workspace API tokens.

Replace or revoke

Create a replacement from the token's actions in Settings. Save it to the client's credential manager, verify authentication and the required task, then revoke the original token. Creating a replacement does not revoke the original.

Revoke a token when its machine is retired, its purpose ends or the credential may have been exposed. If a secret value was also exposed, revoke or rotate that value with its provider; revoking an API token does not invalidate copies of secret values already retrieved.

Legacy tokens

Tokens labeled legacy use broad grants instead of module scopes. Do not describe them as Secrets-only. Existing owner/admin legacy edit access retains compatible value and rollback behavior. Choose explicit module permissions when replacing a legacy token.

Use Connect a machine or agent to verify a new token without revealing a protected value.

AsyncFlux Secrets documentation
Search documentation