Access tokens and permissions

An access token lets a script, a CI job or a tool act as you through the API, the CLI or MCP. You create it on the Developers page of the workspace settings; it works in one workspace and can do only what you allowed. On your own computer, playcode login signs in through the browser instead, with no token to copy.

On this page

Do it yourself

#
  1. Open Settings and choose Developers under the workspace.
  2. Under Access tokens, choose Create access token.
  3. In Name, say what will use it, like Deploy script.
  4. Under What it may do, turn on only what the tool needs: see the table below. Projects and computers is on to start with.
  5. Under Where, choose Everything in your workspace, or Only these projects and pick them.
  6. Under Expires, choose 30 days, 90 days, 1 year or Never. 90 days is chosen to start with.
  7. Choose Create token. If Playcode asks you to confirm it's you, enter the code from the email it sends.
  8. Copy the token: "Copy it now - you won't see this token again." It starts with pc_live_.
  9. Give it to the tool: set the PLAYCODE_TOKEN environment variable, run playcode login --paste, or send it as Authorization: Bearer <token>.

What each permission allows

#
In What it may do Permission What the tool can do
Projects and computers projects:vm Read projects and their files, change files, run commands on a project's computer, publish, open a shell, rename a project
Domains domains:write Look up names, connect domains to projects, edit DNS records. Also buy, transfer and renew domains on the workspace's card: see Limits
Send email mail:send Nothing yet: see Limits
Use AI ai:chat Nothing yet: see Limits

Revoke a token

#

Choose the cross beside the token, then Revoke: "Anything still using this token stops working at once - and everything it minted dies with it." Each row shows the token's last four characters, its permissions, where it reaches, and when and through which door it was last used.

Tools signed in as you

#

Signed in as you lists the tools that signed in through Sign in with Playcode, like the CLI after playcode login or an MCP client: the workspace each one acts in, what it may do, and since when. Choose the cross, then Revoke, to sign a tool out on every computer at once.

If it doesn't work

#

"That is not a Playcode access token (they start with pc_live_ or pc_test_ and are 48 characters)."

#

The CLI got part of the token, or something else. Copy the whole token again, or create a new one if it is lost.

The call is refused with missing_scope

#

The token lacks a permission, which the refusal names, like "needs the domains:write permission". A token's permissions cannot change: create a new token with the permission, and revoke the old one.

"the token is bound to another workspace" or "the token does not reach this project"

#

The call names a workspace or a project outside the token's Where. Create a token that reaches it.

The call is refused with invalid_key

#

The token was revoked or has expired. Create a new one.

"... takes a signed-in person, never a token"

#

Access tokens and webhooks are managed only by a signed-in person, in the app: on the Developers page, or by asking the agent in a chat. A token cannot manage them.

Limits

#
  • A token works in one workspace. Its permissions, its reach and its expiry are fixed when you create it.
  • No token reaches access tokens, webhooks or an app's own settings, such as its email, secrets and AI switch.
  • With Domains, a tool can also buy or transfer a domain on the workspace's card, when you are the workspace's owner or an Admin, and turn on a domain's automatic renewal, which charges the same card. For a purchase or a transfer, the API gives the tool the terms with the price first and takes them back with the call; it does not ask you. Give Domains only to a tool you trust to ask you first.
  • Playcode's email and AI services do not accept access tokens yet. Your app's code uses its secret key instead: Settings, Secret key in the project.
  • Listing projects with a token returns the projects you own in its reach.
  • A token unused for 30 days is worth revoking: its row shows when it was last used.