The Token, Scoped to What It May Read.
From the user menu, open API Tokens and choose New token. Name it, pick the scopes it may read, sites, staff, contractors, incidents, inspections, plant, risks, permits, and choose when it expires, from 7 days to 1 year. The token is shown once. Revoke it from the same screen and it stops immediately.
- Eight read scopes, all read only
- Expiry from 7 days to 1 year; up to 10 tokens per user
- Shown once; revoked the moment you confirm
Personal API tokens 4 of 10
Every token is read-only and carries only the scopes you give it. A token is shown once, at creation, and never again.
- Claude Code · Safety TeamRevoke
incidents:readinspections:readrisks:read - Power BI · Monthly board packRevoke
sites:readcontractors:readstaff:read - Copilot · ProcurementRevoke
contractors:read - Terminal ops · sign-in bookRevoke
sites:readpermits:read
Prefix cf_pat_ · expiry of 7, 30, 60, or 90 days, one year, or a date of your choosing up to one year · revoking takes effect immediately.