Manage Runners Logo
Manage Runners
Documentation menu

Personal access tokens

Create scoped, expiring tokens for the CLI, scripts, CI jobs and AI agents, and revoke them.

A personal access token (PAT) gives a script, a CI job, an agent or the CLI access to your account, limited to the scopes you choose and until it expires. It acts as you: in each organization it can do at most what both its scopes and your role allow.

Create a token

  1. Open Settings (your profile) and go to Personal access tokens.
  2. Select Create token.
  3. Enter a name of up to 96 characters, for example CI deploy agent.
  4. Select the scopes the token needs. Select read-only selects all scopes that only read.
  5. Choose the expiry: 7 days, 30 days, 90 days or 1 year.
  6. Select Create token.

The Create personal access token dialog with read-only scopes selected

The dashboard shows the token once. Copy it into a secret manager immediately; you cannot see it again. Tokens start with mr_pat_. They cannot be extended: create a new one before the old one expires.

Scopes

Scope Dashboard label Allows
profile:read Read profile Read your profile and list your organizations
runners:read Read runners List and read runners and their monitoring data
runners:write Manage runners Create, edit, pause, resume and duplicate runners. This can create paid Hetzner resources. Updating a runner with the CLI, and waiting for a change with the CLI, also need runners:read.
runners:delete Delete runners Delete runners
runners:forget Remove unknown runners Remove Unknown runners from the dashboard
schedules:read Read schedules Read schedules (Pro or Enterprise plan)
schedules:write Manage schedules Create, change, enable, disable and delete schedules (Pro or Enterprise plan)
products:read Read products List server types, locations and prices
providers:ssh-keys:read Read SSH keys List the SSH keys of a Hetzner project
subscriptions:read Read subscription Read the organization’s plan and the available plans

Grant only what the token needs. A token for a monitoring script, for example, needs runners:read only.

Some things are never possible with a token, whatever its scopes: managing billing, creating or changing organizations, members and invitations, and creating or listing tokens. They need a signed-in dashboard session.

Tokens created by the CLI

When you log in with manage-runners auth login or manage-runners setup, the CLI creates a token for itself, named manage-runners-cli, that expires after 30 days and has the read scopes profile:read, runners:read, schedules:read, products:read, providers:ssh-keys:read and subscriptions:read. Add write scopes only when you need them, with --scope. See Authentication.

These tokens appear in the same list as the ones you create in the dashboard.

Use a token

  • CLI: set MANAGE_RUNNERS_TOKEN for one-off use, for example in CI, or store the token with manage-runners auth login --token-stdin. See Authentication.
  • API: send it as Authorization: Bearer <token> to https://api.managerunners.com.

Treat tokens like passwords. Never put them in a repository, a command line or a log.

Review and revoke tokens

The list shows each token’s name, status (Active, Expired or Revoked), scopes, and when it was created, expires and was last used. Scopes that change data are highlighted.

Select Revoke to disable an active token. Scripts, CI jobs and CLI profiles that use it stop working immediately. This cannot be undone. The CLI can also revoke its own token with manage-runners auth logout --revoke.