Personal access tokens
Create scoped, expiring tokens for the CLI, scripts, CI jobs and AI agents, and revoke them.
A personal access token (PAT) gives a script, a CI job, an agent or the CLI access to your account, limited to the scopes you choose and until it expires. It acts as you: in each organization it can do at most what both its scopes and your role allow.
Create a token
- Open Settings (your profile) and go to Personal access tokens.
- Select Create token.
- Enter a name of up to 96 characters, for example
CI deploy agent. - Select the scopes the token needs. Select read-only selects all scopes that only read.
- Choose the expiry: 7 days, 30 days, 90 days or 1 year.
- Select Create token.

The dashboard shows the token once. Copy it into a secret manager immediately; you cannot see it again. Tokens start with mr_pat_. They cannot be extended: create a new one before the old one expires.
Scopes
| Scope | Dashboard label | Allows |
|---|---|---|
profile:read |
Read profile | Read your profile and list your organizations |
runners:read |
Read runners | List and read runners and their monitoring data |
runners:write |
Manage runners | Create, edit, pause, resume and duplicate runners. This can create paid Hetzner resources. Updating a runner with the CLI, and waiting for a change with the CLI, also need runners:read. |
runners:delete |
Delete runners | Delete runners |
runners:forget |
Remove unknown runners | Remove Unknown runners from the dashboard |
schedules:read |
Read schedules | Read schedules (Pro or Enterprise plan) |
schedules:write |
Manage schedules | Create, change, enable, disable and delete schedules (Pro or Enterprise plan) |
products:read |
Read products | List server types, locations and prices |
providers:ssh-keys:read |
Read SSH keys | List the SSH keys of a Hetzner project |
subscriptions:read |
Read subscription | Read the organization’s plan and the available plans |
Grant only what the token needs. A token for a monitoring script, for example, needs runners:read only.
Some things are never possible with a token, whatever its scopes: managing billing, creating or changing organizations, members and invitations, and creating or listing tokens. They need a signed-in dashboard session.
Tokens created by the CLI
When you log in with manage-runners auth login or manage-runners setup, the CLI creates a token for itself, named manage-runners-cli, that expires after 30 days and has the read scopes profile:read, runners:read, schedules:read, products:read, providers:ssh-keys:read and subscriptions:read. Add write scopes only when you need them, with --scope. See Authentication.
These tokens appear in the same list as the ones you create in the dashboard.
Use a token
- CLI: set
MANAGE_RUNNERS_TOKENfor one-off use, for example in CI, or store the token withmanage-runners auth login --token-stdin. See Authentication. - API: send it as
Authorization: Bearer <token>tohttps://api.managerunners.com.
Treat tokens like passwords. Never put them in a repository, a command line or a log.
Review and revoke tokens
The list shows each token’s name, status (Active, Expired or Revoked), scopes, and when it was created, expires and was last used. Scopes that change data are highlighted.
Select Revoke to disable an active token. Scripts, CI jobs and CLI profiles that use it stop working immediately. This cannot be undone. The CLI can also revoke its own token with manage-runners auth logout --revoke.
