Everything that can reach your account from outside the dashboard is listed in one place: Settings → API & MCP. The tab has three parts: creating a token, the tokens you have made, and the apps you have connected.
Personal access tokens
A personal access token is how your own code calls the REST API. Creating one needs the Business plan; on other plans the tab explains what the API includes instead of showing the form.
Creating a token
- Name it after what will use it ("Nightly export", "Grafana"). The name is how you will recognise it when deciding what to revoke.
- Pick scopes. A token can do only what its scopes allow, and there is no "everything" option. Choose the fewest that work:
| Scope | Allows |
|---|---|
domains:read |
Read your domains, their status and DNS. |
domains:write |
Add, change, move and remove your domains, and request checks. |
alerts:read |
Read your alert history. |
scan |
Scan names you do not monitor and run the domain tools; spends lookups. |
- Choose how long it lasts: 30, 90 or 365 days. There is no never-expiring token; when one expires, create a new one and swap it in.
- Choose Create token and copy it from the highlighted panel at the top. This is the only time it is shown.
A request a token's scopes do not cover is refused with insufficient_scope, and the response names the scope it needed.
The token list
Each token shows its scopes, when it was created, when it expires, and when it was last used (updated at most once a minute). A token that has never been used, or has not been used in months, is a good candidate to revoke.
Revoking
Choose Revoke next to a token, or Revoke all. Anything using it is refused from its next request. Revoking cannot be undone; create a new token if you need access again.
Revoke a token straight away if it may have leaked: committed to a repository, pasted in a ticket, or left on a machine you no longer control.
Connected apps
When you approve an AI assistant through the MCP server, it appears under Connected apps with the permissions you granted, when you authorised it, and when it was last used. Connected apps are listed on every plan, so you can always remove one.
Choose Disconnect to remove one app, or Disconnect all. The app loses access at once and would have to ask for your approval again to reconnect.
An app drops off the list by itself once its access has lapsed, which happens after 30 days without use.
When your plan changes
Tokens and connected apps are kept when you change plan. If your new plan does not include the API or the MCP server, each request is refused with a sentence explaining which plan includes it. Upgrade again and they work without any change on your side.
When you delete your account
Deleting your account revokes every token and disconnects every app before the account is removed.
Good practice
- Keep tokens in a secret manager or environment variable, never in source code.
- Use one token per script or system, so revoking one does not break the others.
- Give each token the fewest scopes it needs. A reporting script needs
domains:read, notdomains:write. - Send the token only in the
Authorization: Bearerheader. The API never accepts it in a URL.