API tokens
API tokens are machine credentials for CI, scripts and MCP clients. Each token has one role and expires.
Create a tokenLink to Create a token
- On API tokens, give the token a name, for example "CI pipeline".
- Choose a role: Member, Viewer, Approver or Admin. A token cannot be an owner, and it cannot have a higher role than yours.
- Choose when it expires: 7, 30, 90, 180 or 365 days. The default is 90 days.
- Copy the token now. Agent shows it only one time.
What a token cannot doLink to What a token cannot do
A token never manages people or other tokens. Some calls, such as data export and member roles, accept only a person signed in to the browser.
StatusesLink to Statuses
Active, Expired and Revoked. Revoking a token cannot be undone.
Who can manage tokensLink to Who can manage tokens
Only owners and admins, signed in to the browser.
Checked against the product on 2026-10-05.
Was this helpful?
Related articles
- Members and rolesPeople in your organization have one of five roles: owner, admin, approver, member or viewer. Admins invite people by email.
- Use Agent from Claude, ChatGPT or CodexAdd Agent to Claude, ChatGPT, Claude Code or Codex. The model runs there on your plan and uses Agent's tools to read and assign work.
- Secrets and credentialsAgent encrypts keys and tokens in a vault. It shows only a short hint, never the full value, and never sends a secret out.