Personal Access Tokens (PAT)

Elias Borghoff
Elias Borghoff
  • Updated

Personal access tokens (PATs) let you connect external tools to Oneflow using your own user access. Instead of giving you broad account-level access, a PAT only allows it to work with the information and actions available to you.

This makes PATs a practical choice for connecting an MCP, trying out API requests or building a prototype.

How personal access tokens work

Every personal access token belongs to the user who generated it. When the token is used, Oneflow handles the request as that user. It cannot be used to bypass the user's existing permissions or gain access to additional workspaces, contracts, or features.

Example: If you can only view contracts in certain workspaces, an application using your personal access token will have the same limitation.

When should I use a personal access token?

A personal access token may be suitable when you want to:

  • Connect an MCP client to Oneflow.
  • Explore or test the Oneflow API.
  • Develop a proof of concept or internal tool.

For our native integrations, a regular API token should be used.

Before creating a token

The personal access token feature must first be enabled for your Oneflow account. This can be enabled via the Oneflow Marketplace. You must also have permission to generate tokens.

Once available, you will find a Personal access tokens page in your Oneflow profile.

Allow users to create personal access tokens

INFORMATION
To allow users to create personal access tokens, you must assign the permission through a custom account role.

An administrator must grant the relevant role permission to create personal access tokens.

  1. Go to Admin > Roles.
  2. Open the role you want to update.
  3. Find and enable Allow creation of personal access tokens.
  4. Save your changes.

Users assigned to the role can then create and manage personal access tokens from their profile, provided the feature is enabled for the account.

Create a personal access token

  1. Open your profile in Oneflow.
  2. Go to Personal access tokens.
  3. Select the option to create a new token.
  4. Give the token a name that describes its purpose.
  5. Confirm the creation of the token.
  6. Copy the token and save it in a secure location.
PatToken.gif

Keep your token secure: Anyone who obtains the token may be able to access Oneflow with your permissions. Do not share it or add it directly to source code.

Revoke a token

You can revoke your existing tokens from the Personal access tokens page in your profile.

Revoke a token when you no longer use the connected tool or if you believe the token may have been exposed. If access is still required, create a replacement token and update the relevant use case.

DeletePAT.gif

Personal and regular API tokens compared

Personal access token Regular API token
Created by an individual user for their own use. Created at the account level for API access.
Access is limited by the permissions of the user who created it. Access is not limited by an individual user's permissions.
Provides user-scoped access to Oneflow. Does not support access scoping.
Suitable for MCP connections, testing and development. Suitable for our native integrations that require broad account-level API access.
Created and managed by the user it belongs to. Created and managed from the account's API token settings.

Frequently asked questions

Why can't I see Personal access tokens in my profile?

The feature may not be enabled for your account, or you may not have permission to create tokens. Contact your Oneflow administrator for assistance.

Can an administrator generate a personal token for me?

No. A personal access token must be generated by the user it belongs to.

Does a personal access token give me additional access?

No. The token follows your existing Oneflow permissions and does not grant access to anything you cannot already access.

Which token type should I choose?

Choose a personal access token when an application only needs to operate within your own permissions. If the integration requires broader account-level access, please use a regular API token instead.

Where can I learn more about the Oneflow API?

See the Oneflow API documentation for additional guidance.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request