Managing API Tokens and Connected Apps

Updated Oct 05, 2026

Create, scope, expire and revoke personal access tokens, and see or disconnect the AI assistants you have authorised.

Everything that can reach your account from outside the dashboard is listed in one place: Settings → API & MCP. The tab has three parts: creating a token, the tokens you have made, and the apps you have connected.

Personal access tokens

A personal access token is how your own code calls the REST API. Creating one needs the Business plan; on other plans the tab explains what the API includes instead of showing the form.

Creating a token

  1. Name it after what will use it ("Nightly export", "Grafana"). The name is how you will recognise it when deciding what to revoke.
  2. Pick scopes. A token can do only what its scopes allow, and there is no "everything" option. Choose the fewest that work:
Scope Allows
domains:read Read your domains, their status and DNS.
domains:write Add, change, move and remove your domains, and request checks.
alerts:read Read your alert history.
scan Scan names you do not monitor and run the domain tools; spends lookups.
  1. Choose how long it lasts: 30, 90 or 365 days. There is no never-expiring token; when one expires, create a new one and swap it in.
  2. Choose Create token and copy it from the highlighted panel at the top. This is the only time it is shown.

A request a token's scopes do not cover is refused with insufficient_scope, and the response names the scope it needed.

The token list

Each token shows its scopes, when it was created, when it expires, and when it was last used (updated at most once a minute). A token that has never been used, or has not been used in months, is a good candidate to revoke.

Revoking

Choose Revoke next to a token, or Revoke all. Anything using it is refused from its next request. Revoking cannot be undone; create a new token if you need access again.

Revoke a token straight away if it may have leaked: committed to a repository, pasted in a ticket, or left on a machine you no longer control.

Connected apps

When you approve an AI assistant through the MCP server, it appears under Connected apps with the permissions you granted, when you authorised it, and when it was last used. Connected apps are listed on every plan, so you can always remove one.

Choose Disconnect to remove one app, or Disconnect all. The app loses access at once and would have to ask for your approval again to reconnect.

An app drops off the list by itself once its access has lapsed, which happens after 30 days without use.

When your plan changes

Tokens and connected apps are kept when you change plan. If your new plan does not include the API or the MCP server, each request is refused with a sentence explaining which plan includes it. Upgrade again and they work without any change on your side.

When you delete your account

Deleting your account revokes every token and disconnects every app before the account is removed.

Good practice

  • Keep tokens in a secret manager or environment variable, never in source code.
  • Use one token per script or system, so revoking one does not break the others.
  • Give each token the fewest scopes it needs. A reporting script needs domains:read, not domains:write.
  • Send the token only in the Authorization: Bearer header. The API never accepts it in a URL.

More in API and AI Assistants

Related guides and tutorials.

View all