Personal Access Token (PAT) management. PATs are long-lived, scoped bearer tokens (format: ck_pat_<40 hex chars>) intended for programmatic integrations, automation scripts, CI pipelines, and agentic workflows. Unlike standard JWTs they carry an explicit scope list and can optionally be restricted to a subset of account IDs (allowed_account_ids), enabling the principle of least privilege. Lifecycle: create a PAT via POST /users/self/pats — the full token is returned once and must be stored securely. Use it as Authorization: Bearer ck_pat_... on any supported endpoint. Revoke it via DELETE /users/self/pats/{id} when it is no longer needed. Security best practices: request only the scopes your integration actually needs; set an expires_at for tokens used in ephemeral environments; store the plaintext token in a secret manager, not in source code; rotate PATs periodically and revoke any that may have been exposed.
[Beta] List Personal Access Tokens
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
List the authenticated user's Personal Access Tokens with pagination.
Required scope(s): tokens:read
query Parameters
pageper_pagestatusAn enumeration.
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] List Personal Access Tokens › Responses
Successful Response
[Beta] Create a Personal Access Token
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Creates a new Personal Access Token (PAT) for the authenticated user.
A PAT is a long-lived, scoped bearer token (format: ck_pat_<40 hex chars>) intended for programmatic and agentic integrations — scripts, CI pipelines, third-party tools, and AI agents — where storing a username and password is undesirable.
Unlike a standard JWT obtained via POST /token, a PAT:
- carries an explicit list of granted scopes (least-privilege access control)
- can optionally be restricted to specific account IDs via
allowed_account_ids - does not expire by default, but can be given a hard
expires_atdeadline - can be revoked individually via
DELETE /users/self/pats/{id}without affecting login
The full token plaintext is returned only once in the response — store it securely (e.g. in a secret manager or environment variable). It cannot be retrieved again.
Required scope(s): tokens:admin
[Beta] Create a Personal Access Token › Request Body
name^[\w\s\-.,!@#%()+='\… · requiredHuman-readable token name
scopesRequested scopes (broad or granular)
allowed_account_idsRestrict this token to a specific set of account IDs. When set, the token will be rejected with 403 Forbidden on any request that operates on an account not in this list, even if the owning user has access to that account. Use this to apply the principle of least privilege in multi-account contexts — for example, grant an automation token access to only the accounts it actually needs to manage. Null (default) means the token is unrestricted and inherits all account access rights of the owning user.
expires_atExpiry as a Unix timestamp (seconds since epoch). Null = never expires.
[Beta] Create a Personal Access Token › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
plaintextFull token plaintext (shown once; store securely)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null
[Beta] List another user's Personal Access Tokens
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
List Personal Access Tokens for a specific user. Requires admin access.
Required scope(s): tokens:admin
path Parameters
user_idTarget user ID
Target user ID
query Parameters
pageper_pagestatusAn enumeration.
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] List another user's Personal Access Tokens › Responses
Successful Response
[Beta] Get PAT audit log (self)
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Returns a paginated audit trail of PAT lifecycle events for the authenticated user.
Required scope(s): tokens:read
query Parameters
key_prefixFilter by token key prefix
Filter by token key prefix
actionFilter by action: create, update, or revoke
Filter by action: create, update, or revoke
pagePage number
Page number
per_pageResults per page (max 100)
Results per page (max 100)
start_timeFilter from timestamp (Unix epoch)
Filter from timestamp (Unix epoch)
end_timeFilter to timestamp (Unix epoch)
Filter to timestamp (Unix epoch)
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Get PAT audit log (self) › Responses
Successful Response
[Beta] Get PAT audit log (admin)
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Returns a paginated audit trail of PAT lifecycle events for a specific user.
Required scope(s): tokens:admin
path Parameters
user_idTarget user ID
Target user ID
query Parameters
key_prefixFilter by token key prefix
Filter by token key prefix
actionFilter by action: create, update, or revoke
Filter by action: create, update, or revoke
pagePage number
Page number
per_pageResults per page (max 100)
Results per page (max 100)
start_timeFilter from timestamp (Unix epoch)
Filter from timestamp (Unix epoch)
end_timeFilter to timestamp (Unix epoch)
Filter to timestamp (Unix epoch)
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Get PAT audit log (admin) › Responses
Successful Response
[Beta] Get Personal Access Token metadata
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Get metadata for a specific Personal Access Token by its key prefix.
Required scope(s): tokens:read
path Parameters
key_prefixToken key prefix (first 12 chars)
Token key prefix (first 12 chars)
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Get Personal Access Token metadata › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null
[Beta] Revoke a Personal Access Token
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Soft-revoke a Personal Access Token. Cannot revoke your own active token.
Required scope(s): tokens:admin
path Parameters
key_prefixToken key prefix
Token key prefix
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Revoke a Personal Access Token › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null
[Beta] Update a Personal Access Token
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Update the name, scopes, or allowed account IDs of a PAT. Cannot update your own active token.
Required scope(s): tokens:admin
path Parameters
key_prefixToken key prefix
Token key prefix
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Update a Personal Access Token › Request Body
name^[\w\s\-.,!@#%()+='\…scopesNew scope list (granular)
allowed_account_ids[Beta] Update a Personal Access Token › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null
[Beta] Get another user's Personal Access Token metadata
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Get metadata for a specific Personal Access Token belonging to another user. Requires admin access.
Required scope(s): tokens:admin
path Parameters
user_idTarget user ID
Target user ID
key_prefixToken key prefix (first 12 chars)
Token key prefix (first 12 chars)
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Get another user's Personal Access Token metadata › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null
[Beta] Revoke another user's Personal Access Token
⚠ Beta: Personal Access Tokens are a beta feature. During the beta period, existing tokens may be revoked without notice if the scope model is updated. If authentication unexpectedly fails with a 401, simply create a new token.
Soft-revoke a Personal Access Token belonging to another user. Requires admin access.
Required scope(s): tokens:admin
path Parameters
user_idTarget user ID
Target user ID
key_prefixToken key prefix
Token key prefix
query Parameters
account_idOptional Account ID to be used for the request
Optional Account ID to be used for the request
[Beta] Revoke another user's Personal Access Token › Responses
Successful Response
key_prefixPublic identifier (first 12 chars of token)
nameHuman-readable token name
scopesGranted granular scopes
statusToken status: active or revoked
created_atCreation timestamp (Unix)
allowed_account_idsNull = unrestricted. List = restricted to these account IDs.
expires_atExpiry timestamp (Unix) or null
revoked_atRevocation timestamp (Unix) or null