Skip to content
Published

Last reviewed: 2026-07-29

Service tokens

Create least-privilege service tokens in the CodeCleared UI, rotate them safely, and handle multi-organization personal tokens.

Create and protect a service token

Create service tokens in the CodeCleared UI under Settings → Service tokens → Tokens (/settings/service-tokens?tab=tokens) for an organization or an approved automation identity. The token value is shown once. Copy it directly into your secret manager; if it is lost, create a replacement rather than searching logs or sharing it in chat.

MCP client setup snippets live on the sibling MCP tab (?tab=mcp). See MCP integration.

Choose least-privilege scopes

Grant only the scopes the integration needs:

  • Read-only result collection: scan read access (scan:read or equivalent).
  • Scan creation: scan write / scan:all as needed.
  • Package Finder: package-finder:read.
  • Finding triage: finding:read to list ignores; finding:write to create or remove them. These scopes are not implied by scan:all. Only triage, admin, and owner may assign finding scopes when minting a token.
  • License governance: policy:read to list allowances and overrides; policy:write to create/delete project-unit or repository allowances and overrides (minting requires triage+); policy:admin for organization-wide package allowances and whitelist append (minting requires admin/owner). These scopes are not implied by scan:all. Saving an allowance does not start a scan.

Review scopes and organization access before deploying the token.

Rotate without downtime

Create a replacement token, update the integration’s secret, verify a safe request, then revoke the old token. Never commit, log, screenshot, or place a token in a URL. Treat an exposed token as compromised and rotate it immediately.

Multi-organization access

A personal token that can access multiple organizations may require organizationId on some calls. Set it explicitly in automation and verify the returned organization before reading data or creating work. Prefer an organization-specific token for client or production workflows.

Related documentation