# Access tokens and permissions

> Create an access token for a script, a CI job or a tool that acts as you. What each permission allows, where it reaches, and how to revoke it.
> Source: https://playcode.io/docs/developers/tokens-and-permissions - last reviewed 2026-10-10.

An access token lets a script, a CI job or a tool act as you through the API, the CLI or MCP. You create it on the **Developers** page of the workspace settings; it works in one workspace and can do only what you allowed. On your own computer, `playcode login` signs in through the browser instead, with no token to copy.

## Do it yourself

1. Open **Settings** and choose **Developers** under the workspace.
2. Under **Access tokens**, choose **Create access token**.
3. In **Name**, say what will use it, like `Deploy script`.
4. Under **What it may do**, turn on only what the tool needs: see the table below. **Projects and computers** is on to start with.
5. Under **Where**, choose **Everything in** your workspace, or **Only these projects** and pick them.
6. Under **Expires**, choose **30 days**, **90 days**, **1 year** or **Never**. **90 days** is chosen to start with.
7. Choose **Create token**. If Playcode asks you to confirm it's you, enter the code from the email it sends.
8. Copy the token: "Copy it now - you won't see this token again." It starts with `pc_live_`.
9. Give it to the tool: set the `PLAYCODE_TOKEN` environment variable, run `playcode login --paste`, or send it as `Authorization: Bearer <token>`.

> [!WARNING]
> A token is a password for your workspace. Never put it in code, a chat or a URL, and keep it in your CI's or your server's secret store.

### What each permission allows

| In **What it may do** | Permission | What the tool can do |
|---|---|---|
| **Projects and computers** | `projects:vm` | Read projects and their files, change files, run commands on a project's computer, publish, open a shell, rename a project |
| **Domains** | `domains:write` | Look up names, connect domains to projects, edit DNS records. Also buy, transfer and renew domains on the workspace's card: see Limits |
| **Send email** | `mail:send` | Nothing yet: see Limits |
| **Use AI** | `ai:chat` | Nothing yet: see Limits |

### Revoke a token

Choose the cross beside the token, then **Revoke**: "Anything still using this token stops working at once - and everything it minted dies with it." Each row shows the token's last four characters, its permissions, where it reaches, and when and through which door it was last used.

### Tools signed in as you

**Signed in as you** lists the tools that signed in through Sign in with Playcode, like the CLI after `playcode login` or an MCP client: the workspace each one acts in, what it may do, and since when. Choose the cross, then **Revoke**, to sign a tool out on every computer at once.

## If it doesn't work

### "That is not a Playcode access token (they start with pc_live_ or pc_test_ and are 48 characters)."

The CLI got part of the token, or something else. Copy the whole token again, or create a new one if it is lost.

### The call is refused with `missing_scope`

The token lacks a permission, which the refusal names, like "needs the domains:write permission". A token's permissions cannot change: create a new token with the permission, and revoke the old one.

### "the token is bound to another workspace" or "the token does not reach this project"

The call names a workspace or a project outside the token's **Where**. Create a token that reaches it.

### The call is refused with `invalid_key`

The token was revoked or has expired. Create a new one.

### "... takes a signed-in person, never a token"

Access tokens and webhooks are managed only by a signed-in person, in the app: on the **Developers** page, or by asking the agent in a chat. A token cannot manage them.

## Limits

- A token works in one workspace. Its permissions, its reach and its expiry are fixed when you create it.
- No token reaches access tokens, webhooks or an app's own settings, such as its email, secrets and AI switch.
- With **Domains**, a tool can also buy or transfer a domain on the workspace's card, when you are the workspace's owner or an Admin, and turn on a domain's automatic renewal, which charges the same card. For a purchase or a transfer, the API gives the tool the terms with the price first and takes them back with the call; it does not ask you. Give **Domains** only to a tool you trust to ask you first.
- Playcode's email and AI services do not accept access tokens yet. Your app's code uses its secret key instead: **Settings**, **Secret key** in the project.
- Listing projects with a token returns the projects you own in its reach.
- A token unused for 30 days is worth revoking: its row shows when it was last used.
