Access tokens & automation
Console access tokens are scoped bearer credentials for scripts and CI: pull usage, rotate keys, export logs — without a browser session.
Create one
Settings › Organization › Access tokens (organization owner). Pick scopes; the token is shown once. Up to 20 per organization. A token acts with its owner's role, never more.
scopeallows
usage:readproject and organization usage, CSV
logs:readrequest log, detail, NDJSON export
keys:readlist keys
keys:writecreate, edit, rotate, disable and enable keys (never delete)
billing:readbalance, transactions, statements
projects:readprojects
projects:writecreate, rename, archive projects; project budgets; project webhooks
members:readmembers
Use it
curl
# Set once in your shell: PROJECT (the project id from the console) and # TF_ACCESS_TOKEN (the access token, shown once when you create it). curl "/api/projects/$PROJECT/usage?groupBy=tag:env" -H "Authorization: Bearer $TF_ACCESS_TOKEN" # no cookie, no X-Requested-With: bearer requests are not subject to CSRF # rotate a key from a deployment pipeline (keys:write): the new secret is returned once, # the old key keeps working for graceHours so you can roll it out curl -X POST "/api/api-keys/$KEY_ID/rotate" -H "Authorization: Bearer $TF_ACCESS_TOKEN" \ -H 'content-type: application/json' -d '{"graceHours": 24}'
Tokens cannot mint tokens, delete keys, read a key back, change the organization budget or billing, manage members, or act on another organization. Every call is attributed to the token in the audit log; revoke from the same page.