chainsaw token
Manage API tokens (PATs and AI-agent credentials)
Manage API tokens (PATs and AI-agent credentials)
| Subcommand | What it does |
|---|---|
chainsaw token create | Mint a new API token (cleartext shown once) |
chainsaw token list | List API tokens in the current org |
chainsaw token revoke | Revoke a token (irreversible) |
chainsaw token rotate | Rotate a token’s secret (cleartext shown once) |
chainsaw token [command]
List, mint, rotate, and revoke the API tokens your org uses to drive Chain305 itself — the CLI, the management API, and MCP clients such as an AI coding agent. These are NOT the credentials that go in .npmrc / pip.conf to install packages; those are client credentials, managed via chainsaw auth client.
chainsaw token create
Mint a new API token (cleartext shown once)
chainsaw token create [flags]
Mint a new API token and print the cleartext secret exactly once. Save it immediately — the server does not retain cleartext and cannot redisplay it. Use –preset for the canonical scope presets (manage-readonly, manage-propose, client-setup, custom), or pass –scopes for an explicit permission list.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--agent-kind | string | — | Agent kind (required when –key-type=agent): claude-code, cursor, windsurf, mcp-generic |
--allow-mutations | bool | — | Allow mutation tools (propose/apply without human approval) |
--expires-at | string | — | Expiry as RFC3339 (e.g. 2026-12-31T00:00:00Z); omit for unbounded |
--json | bool | — | Print the created token payload as JSON (cleartext included once) |
--key-type | string | personal | Key type: personal or agent |
--name | string | — | Human-readable name (required) |
--preset | string | — | Scope preset: manage-readonly, manage-propose, client-setup, or custom |
--scopes | stringSlice | — | Explicit permission list (e.g. policies:read,exceptions:manage). Intersected with preset if both supplied. |
The global flags apply here too.
chainsaw token list
List API tokens in the current org
chainsaw token list [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Output as JSON |
--key-type | string | — | Filter by key_type: personal or agent |
The global flags apply here too.
chainsaw token revoke
Revoke a token (irreversible)
chainsaw token revoke <token-id | name> [flags]
Revoke a token by id (ak-…) or by the name shown in chainsaw token list. The token stops authenticating immediately. This is irreversible — there is no un-revoke verb. Use –yes to skip the confirmation prompt in scripts.
A name shared by two live tokens is refused rather than guessed at; the error lists the ids so you can pick one. CLI keys are named cli:<host>@<date>, so minting two in a day produces exactly that.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--dry-run | bool | — | Preview what would be revoked without actually revoking |
--yes | bool | — | Skip confirmation prompt |
The global flags apply here too.
chainsaw token rotate
Rotate a token’s secret (cleartext shown once)
chainsaw token rotate <token-id> [flags]
Rotate an existing token: server generates a new cleartext secret, keeps the same id/name/scopes/expires_at, and invalidates the old secret immediately. The new cleartext is shown ONCE — save it before the command returns. Every consumer of the old secret starts failing the moment this returns and there is no un-rotate, so the command confirms first. Use –yes to skip the prompt in scripts, and –json for CI consumption.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | — | Print the rotated token payload as JSON (cleartext included once) |
--yes | bool | — | Skip confirmation prompt |
The global flags apply here too.