Developers · API Tokens

Personal access tokens, scoped to exactly what you need

Self-issued personal access tokens are issued from Profile → Access Tokens, with a 30-day default validity and a choice of read-only or read-write scope - so an integration or AI assistant gets exactly the access it needs and nothing more.

  • ✓Free trial
  • ✓No credit card
  • ✓Free onboarding
Profile → Access TokensPinned to Acme Corp · Head Office

New token

Read-onlyRead-writeValid 30 days

12|crmleaf_pat_••••••••••••••••7f3a

  • Claude (MCP)

    Expires in 30 days

    Read-only
  • Warehouse sync

    Expires in 18 days

    Read-write
  • Reporting script

    Expires in 4 days

    Read-only

How it works

Issuing a token

  1. 1

    Go to Profile

    Open Profile → Access Tokens.

  2. 2

    Choose scope

    Pick read-only or read-write, matching what the integration actually needs.

  3. 3

    Issue the token

    The token is created, valid for 30 days by default.

  4. 4

    Use it

    The token powers API integrations and MCP (AI assistant) access alike.

  5. 5

    Review & revoke

    Review and revoke tokens as a regular part of your security process.

What to know

Scoped, time-bound, auditable

Read-only or read-write

Choose the narrowest scope that gets the job done for each token.

30-day default expiry

Tokens default to a 30-day validity, keeping stale credentials from lingering.

Powers API & MCP alike

The same token type authenticates both direct API calls and MCP (AI assistant) access.

In detail

How tokens fit the platform

Tokens are user-issued and pinned to their company and organization, using Laravel Sanctum under the hood (the same mechanism behind the mobile app's own API). They don't require 2FA separately from your account's own login security.

  • Sanctum
  • Profile → Access Tokens
  • MCP
  • REST API

Built in

  • Read-only or read-write scoping, chosen per token
  • 30-day default validity
  • Pinned to the issuing user's company and organization
  • Powers both REST API calls and MCP (AI assistant) access
FAQ

Frequently asked questions

Issue your first token

Get a scoped, time-bound credential for your integration or AI assistant in under a minute.