# Personal access tokens

> Create scoped, expiring tokens for the CLI, scripts, CI jobs and AI agents, and revoke them.

Source: https://managerunners.com/docs/manual/access-tokens/

A personal access token (PAT) gives a script, a CI job, an agent or the [CLI](https://managerunners.com/docs/cli/) access to your account, limited to the scopes you choose and until it expires. It acts as you: in each organization it can do at most what both its scopes and your role allow.

## Create a token

1. Open **Settings** (your profile) and go to **Personal access tokens**.
2. Select **Create token**.
3. Enter a name of up to 96 characters, for example `CI deploy agent`.
4. Select the scopes the token needs. **Select read-only** selects all scopes that only read.
5. Choose the expiry: 7 days, 30 days, 90 days or 1 year.
6. Select **Create token**.

![The Create personal access token dialog with read-only scopes selected](https://managerunners.com/docs/screenshots/access-tokens-light.webp)

The dashboard shows the token once. Copy it into a secret manager immediately; you cannot see it again. Tokens start with `mr_pat_`. They cannot be extended: create a new one before the old one expires.

## Scopes

| Scope | Dashboard label | Allows |
| --- | --- | --- |
| `profile:read` | Read profile | Read your profile and list your organizations |
| `runners:read` | Read runners | List and read runners and their monitoring data |
| `runners:write` | Manage runners | Create, edit, pause, resume and duplicate runners. This can create paid Hetzner resources. Updating a runner with the CLI, and waiting for a change with the CLI, also need `runners:read`. |
| `runners:delete` | Delete runners | Delete runners |
| `runners:forget` | Remove unknown runners | Remove **Unknown** runners from the dashboard |
| `schedules:read` | Read schedules | Read schedules (Pro or Enterprise plan) |
| `schedules:write` | Manage schedules | Create, change, enable, disable and delete schedules (Pro or Enterprise plan) |
| `products:read` | Read products | List server types, locations and prices |
| `providers:ssh-keys:read` | Read SSH keys | List the SSH keys of a Hetzner project |
| `subscriptions:read` | Read subscription | Read the organization's plan and the available plans |

Grant only what the token needs. A token for a monitoring script, for example, needs `runners:read` only.

Some things are never possible with a token, whatever its scopes: managing billing, creating or changing organizations, members and invitations, and creating or listing tokens. They need a signed-in dashboard session.

## Tokens created by the CLI

When you log in with `manage-runners auth login` or `manage-runners setup`, the CLI creates a token for itself, named `manage-runners-cli`, that expires after 30 days and has the read scopes `profile:read`, `runners:read`, `schedules:read`, `products:read`, `providers:ssh-keys:read` and `subscriptions:read`. Add write scopes only when you need them, with `--scope`. See [Authentication](https://managerunners.com/docs/cli/authentication/).

These tokens appear in the same list as the ones you create in the dashboard.

## Use a token

- **CLI:** set `MANAGE_RUNNERS_TOKEN` for one-off use, for example in CI, or store the token with `manage-runners auth login --token-stdin`. See [Authentication](https://managerunners.com/docs/cli/authentication/).
- **API:** send it as `Authorization: Bearer <token>` to `https://api.managerunners.com`.

Treat tokens like passwords. Never put them in a repository, a command line or a log.

## Review and revoke tokens

The list shows each token's name, status (**Active**, **Expired** or **Revoked**), scopes, and when it was created, expires and was last used. Scopes that change data are highlighted.

Select **Revoke** to disable an active token. Scripts, CI jobs and CLI profiles that use it stop working immediately. This cannot be undone. The CLI can also revoke its own token with `manage-runners auth logout --revoke`.
