Access tokens
A personal access token lets your coding agent, the CLI or a script act as you on one workspace. Tokens start with apx_pat_.
Create a token
- Open Workspace settings → Coding agents in the workspace your agent should build in.
- Name the token, pick its scopes and, optionally, an expiry.
- Copy the token. It is shown once. Appbricx stores only a hash and can't show it again.
- Use the copy-paste config on the same screen to connect Claude Code or Cursor, or see Build with your coding agent.
The CLI can also mint one: appbricx login --api https://appbricx.com/api --email … --password … creates a token with all three scopes. See Developer CLI.
Scopes
| Scope | Allows |
|---|---|
read | Projects, contracts, check, verify, screenshots, data queries, logs, the guide, component checks |
apply | Create projects, apply and patch contracts |
deploy | Publish to production or preview |
The default is read + apply: the agent can build and verify in dev but not publish. Add deploy only when you want the agent to ship. A call without the scope answers 403 FORBIDDEN_SCOPE.
Workspace binding
- A token belongs to one user and one workspace. It reaches only that workspace's projects; any other project answers "Project not found".
- It acts with your role. Writes need a non-viewer role in the workspace.
- A workspace viewer can only mint read tokens.
- If you are removed from the workspace, your tokens for it stop working at once.
Expiry
Set an expiry between 1 and 366 days, or none. An expired token answers 401 UNAUTHENTICATED("Token expired"). Create a new one and update your agent's environment.
Where tokens work
- The MCP server (
/api/mcp) and the developer API (/api/dev/v1), which the CLI uses. - Nowhere else. A token can't reach billing, admin or workspace settings, so a leaked agent token can't change them.
- A token can't mint another token. Minting needs a signed-in session, so a token can never widen itself.
Revoke a token
Revoke it in Workspace settings → Coding agents. It stops working on the next request. From a script:
# list your tokens (id, name, prefix, scopes, expiry, last used)
curl -sS https://appbricx.com/api/dev/v1/tokens \
-H "Authorization: Bearer $APPBRICX_TOKEN"
# revoke one
curl -sS -X DELETE https://appbricx.com/api/dev/v1/tokens/<token-id> \
-H "Authorization: Bearer $APPBRICX_TOKEN"The list shows each token's first characters (its prefix) and when it was last used, so you can tell which one to revoke.
Keep tokens safe
- Store the token in an environment variable (
APPBRICX_TOKEN) or a secret manager. In CI, use the CI's secret store. - Never commit a token. The MCP configs in the repo and the output of
appbricx mcp-configreferenceAPPBRICX_TOKENinstead of containing it, so.mcp.jsoncan be committed safely. - If you pasted a token into
claude mcp add --header …, it is saved in your local Claude Code config. Don't share that file. - Use one token per agent or machine, give it the smallest scopes it needs, and set an expiry.
- Revoke a token as soon as you think it leaked.