Access tokens & automation

Console access tokens are scoped bearer credentials for scripts and CI: pull usage, rotate keys, export logs — without a browser session.

Create one

Settings › Organization › Access tokens (organization owner). Pick scopes; the token is shown once. Up to 20 per organization. A token acts with its owner's role, never more.

scopeallows
usage:readproject and organization usage, CSV
logs:readrequest log, detail, NDJSON export
keys:readlist keys
keys:writecreate, edit, rotate, disable and enable keys (never delete)
billing:readbalance, transactions, statements
projects:readprojects
projects:writecreate, rename, archive projects; project budgets; project webhooks
members:readmembers

Use it

curl
# Set once in your shell: PROJECT (the project id from the console) and
# TF_ACCESS_TOKEN (the access token, shown once when you create it).
curl "/api/projects/$PROJECT/usage?groupBy=tag:env" -H "Authorization: Bearer $TF_ACCESS_TOKEN"
# no cookie, no X-Requested-With: bearer requests are not subject to CSRF

# rotate a key from a deployment pipeline (keys:write): the new secret is returned once,
# the old key keeps working for graceHours so you can roll it out
curl -X POST "/api/api-keys/$KEY_ID/rotate" -H "Authorization: Bearer $TF_ACCESS_TOKEN" \
  -H 'content-type: application/json' -d '{"graceHours": 24}'

Tokens cannot mint tokens, delete keys, read a key back, change the organization budget or billing, manage members, or act on another organization. Every call is attributed to the token in the audit log; revoke from the same page.