Permissions and tokens
Choose workspace scopes, create a machine token, and replace or revoke access.
Two checks apply to a scoped token: its explicit module permissions and its actor's current authority in the workspace. Adding a permission cannot exceed that actor's role or the issuer's grants. Secrets permissions apply across all environments in the token's one workspace.
Choose Secrets permissions
| Permission | Scope | Allows | Eligible actor roles |
|---|---|---|---|
| Read metadata | secrets:read |
Status, types, environments, secret lists, history, audit activity and metadata comparison | Owner, admin, member, guest |
| Manage | secrets:edit |
Enable Secrets, manage environments, create/update/delete/import secrets and save changes | Owner, admin |
| Read secret values | secrets:values |
Reveal a current or historical value and export an environment | Owner, admin |
Select permissions explicitly. Manage does not automatically include Read metadata or Read secret values. Value comparison requires secrets:read and secrets:values. Rollback requires secrets:edit and secrets:values.
Metadata can contain display values: certificate, publishable and config values are unmasked, and connection strings are partly masked. Do not treat metadata access as a promise that no value can be seen. Management access can change a value's type, including its display behavior.
Create a token
- Sign in as a human owner/admin and select the intended workspace.
- Open Settings → API tokens and choose Create API token.
- Enter a name identifying the client, such as
docs-demo-laptop. - Choose Acts as: yourself or an eligible agent in this workspace. The default is your own actor. Another person's identity cannot be selected.
- Select only the required module permissions and an expiry. The default is 30 days; the maximum is 365 days. The API accepts a minimum of 60 seconds.
- Create the token and save it immediately in the client credential manager. It is shown once. Closing the panel loses that disclosure.
A token's ID is safe to use to identify it in an access request; its bearer value is a credential. List and self-inspection endpoints return metadata, not that bearer value.
Live authority and expiry
Personal tokens remain tied to live membership grants and identity status. Agent tokens remain tied to their active actor and role. Removing access, disabling an identity, expiring or revoking a credential can cause requests that once worked to be refused.
A scoped token can call only explicitly permitted API routes. It cannot issue tokens or use the human-only management and skill-download endpoints. Identity-provider sign-in credentials are not interchangeable with these workspace API tokens.
Replace or revoke
Create a replacement from the token's actions in Settings. Save it to the client's credential manager, verify authentication and the required task, then revoke the original token. Creating a replacement does not revoke the original.
Revoke a token when its machine is retired, its purpose ends or the credential may have been exposed. If a secret value was also exposed, revoke or rotate that value with its provider; revoking an API token does not invalidate copies of secret values already retrieved.
Legacy tokens
Tokens labeled legacy use broad grants instead of module scopes. Do not describe them as Secrets-only. Existing owner/admin legacy edit access retains compatible value and rollback behavior. Choose explicit module permissions when replacing a legacy token.
Use Connect a machine or agent to verify a new token without revealing a protected value.