Read-only or read-write
Choose the narrowest scope that gets the job done for each token.
Self-issued personal access tokens are issued from Profile → Access Tokens, with a 30-day default validity and a choice of read-only or read-write scope - so an integration or AI assistant gets exactly the access it needs and nothing more.
New token
12|crmleaf_pat_••••••••••••••••7f3a
Claude (MCP)
Expires in 30 days
Warehouse sync
Expires in 18 days
Reporting script
Expires in 4 days
How it works
Open Profile → Access Tokens.
Pick read-only or read-write, matching what the integration actually needs.
The token is created, valid for 30 days by default.
The token powers API integrations and MCP (AI assistant) access alike.
Review and revoke tokens as a regular part of your security process.
What to know
Choose the narrowest scope that gets the job done for each token.
Tokens default to a 30-day validity, keeping stale credentials from lingering.
The same token type authenticates both direct API calls and MCP (AI assistant) access.
In detail
Tokens are user-issued and pinned to their company and organization, using Laravel Sanctum under the hood (the same mechanism behind the mobile app's own API). They don't require 2FA separately from your account's own login security.
Get a scoped, time-bound credential for your integration or AI assistant in under a minute.