Why this matters
Personal Access Tokens let your scripts, integrations, and tools authenticate to the API instead of your password. Each token carries only the permissions (scopes) you grant it, and can be revoked at any time.
Because a token is scoped and revocable, it's safer than sharing your password: you decide exactly what each integration can do, and you can cut off access instantly without changing your own credentials.
Beta feature
Personal Access Tokens are currently in Beta. The screens and options may change as the feature evolves.
What you can use a token for
A Personal Access Token is how you let something other than the web app act on your account through the API. Typical uses include:
- Connecting your own app or website - sync new sign-ups into a contact list, or trigger an email when someone completes an action.
- Automating routine work - run a scheduled script that imports contacts, updates segments, or exports reports on its own.
- Sending transactional email through the API - use the Email API from your back end for receipts, password resets, and notifications.
- Wiring up no-code and integration tools - authenticate a workflow in a tool that asks for an API token.
- Building and testing integrations - developers use a scoped token while building, then swap in a tighter one for production.
In short: whenever a tool asks you for an API token or key to connect to your account, a Personal Access Token is what you create and paste in — instead of ever handing over your password.
Opening Personal Access Tokens
-
In the left menu, open Settings.
-
Under the Developer heading, click Personal Access Tokens.

The page lists your tokens and shows how many you've created against your limit (for example, 1 / 25 tokens).
Creating a token
-
Click Create token at the top right.
-
Enter a Token name that describes where the token will be used (for example, My Integration). A clear name makes tokens easy to tell apart later.
-
Choose an Expiration: Never, 30 days, 60 days, 1 year, or Custom.
-
Grant permissions. Either pick a preset under Start from a template — Read-only (all), Full access, Campaigns manager, Contact manager, or Developer — or expand the scope groups (Audience, Suppressions, Campaigns, Templates, Email API, Forms, Deliverability, Webhooks, Analytics, Account) and check exactly what the token needs.
-
Click Create.

Copy your token right away
Copy the token as soon as it's created and store it somewhere safe — treat it like a password. Never commit it to source control or share it in plain text. If a token is ever exposed, revoke it and create a new one.
Understanding scopes
Scopes define what a token is allowed to do. Grant only the scopes an integration actually needs — this limits the damage if the token is ever leaked (the principle of least privilege).
Scopes are grouped by area, and each token's row shows a summary of what it can access (for example, Audience · 20, Suppressions · 3, Campaigns · 7). The Start from a template presets are a quick way to apply a common set of scopes:
- Read-only (all) - can read across areas, but make no changes.
- Full access - every scope; use sparingly.
- Campaigns manager - focused on campaign work.
- Contact manager - focused on audiences and contacts.
- Developer - a developer-oriented set for building integrations.
Managing your tokens
The tokens list shows each token's Name, Scopes, Status, Created date, and Expires date. Use the tabs to filter by status: Active, Revoked, Expired, or All.
Each row has actions to:
- View the token's details and scopes.
- Edit the token (for example, rename it or adjust its scopes).
- Delete / revoke the token, which invalidates it immediately.
Rotate and prune regularly
Give each integration its own token, review the list from time to time, and revoke any token you no longer recognize or use. One token per integration means you can revoke a single one without breaking the others.
Related articles
- Your Account Panel: Client ID and Usage - Find the account number some integrations require
- Getting started with the Email API - Authenticate and send your first API request
- Multi-factor authentication (MFA) - Add another layer of security to your account