chainsaw token

Manage API tokens (PATs and AI-agent credentials)

Manage API tokens (PATs and AI-agent credentials)

SubcommandWhat it does
chainsaw token createMint a new API token (cleartext shown once)
chainsaw token listList API tokens in the current org
chainsaw token revokeRevoke a token (irreversible)
chainsaw token rotateRotate a token’s secret (cleartext shown once)
chainsaw token [command]

List, mint, rotate, and revoke the API tokens your org uses to drive Chain305 itself — the CLI, the management API, and MCP clients such as an AI coding agent. These are NOT the credentials that go in .npmrc / pip.conf to install packages; those are client credentials, managed via chainsaw auth client.

chainsaw token create

Mint a new API token (cleartext shown once)

chainsaw token create [flags]

Mint a new API token and print the cleartext secret exactly once. Save it immediately — the server does not retain cleartext and cannot redisplay it. Use –preset for the canonical scope presets (manage-readonly, manage-propose, client-setup, custom), or pass –scopes for an explicit permission list.

Flags

FlagTypeDefaultDescription
--agent-kindstring—Agent kind (required when –key-type=agent): claude-code, cursor, windsurf, mcp-generic
--allow-mutationsbool—Allow mutation tools (propose/apply without human approval)
--expires-atstring—Expiry as RFC3339 (e.g. 2026-12-31T00:00:00Z); omit for unbounded
--jsonbool—Print the created token payload as JSON (cleartext included once)
--key-typestringpersonalKey type: personal or agent
--namestring—Human-readable name (required)
--presetstring—Scope preset: manage-readonly, manage-propose, client-setup, or custom
--scopesstringSlice—Explicit permission list (e.g. policies:read,exceptions:manage). Intersected with preset if both supplied.

The global flags apply here too.

chainsaw token list

List API tokens in the current org

chainsaw token list [flags]

Flags

FlagTypeDefaultDescription
--jsonbool—Output as JSON
--key-typestring—Filter by key_type: personal or agent

The global flags apply here too.

chainsaw token revoke

Revoke a token (irreversible)

chainsaw token revoke <token-id | name> [flags]

Revoke a token by id (ak-…) or by the name shown in chainsaw token list. The token stops authenticating immediately. This is irreversible — there is no un-revoke verb. Use –yes to skip the confirmation prompt in scripts.

A name shared by two live tokens is refused rather than guessed at; the error lists the ids so you can pick one. CLI keys are named cli:<host>@<date>, so minting two in a day produces exactly that.

Flags

FlagTypeDefaultDescription
--dry-runbool—Preview what would be revoked without actually revoking
--yesbool—Skip confirmation prompt

The global flags apply here too.

chainsaw token rotate

Rotate a token’s secret (cleartext shown once)

chainsaw token rotate <token-id> [flags]

Rotate an existing token: server generates a new cleartext secret, keeps the same id/name/scopes/expires_at, and invalidates the old secret immediately. The new cleartext is shown ONCE — save it before the command returns. Every consumer of the old secret starts failing the moment this returns and there is no un-rotate, so the command confirms first. Use –yes to skip the prompt in scripts, and –json for CI consumption.

Flags

FlagTypeDefaultDescription
--jsonbool—Print the rotated token payload as JSON (cleartext included once)
--yesbool—Skip confirmation prompt

The global flags apply here too.