API tokens

Create, use and revoke the API tokens that let AI assistants reach your data. Each token belongs to one organization and is shown only once.

An API token lets an AI assistant, like Claude or ChatGPT, reach your organization’s data through Orcabase’s MCP server. Each token belongs to one organization and can only ever see that organization.

Create a token

  1. Go to Settings then API Tokens then New token.
  2. Name it after where it’ll be used, like “Claude, Jane’s laptop”, and click Create token.
  3. Click Copy token and paste it into your assistant. See Set up Claude and ChatGPT.

You’ll only see it once

Orcabase stores a scrambled version of the token that it can check, not the token itself, so it can’t show it again. If you lose it, revoke it and make a new one.

The token list

ColumnShows
NameThe name you gave it.
StatusActive, or Revoked.
CreatedWhen it was made.
Last usedWhen an assistant last used it, or Never. A quick way to spot tokens nobody needs.

Revoke a token

Click Revoke token next to it. It stops working on the very next request, with nothing to wait for. Things created with it stay.

Good habits

  • One token per person and per device, so you can revoke one without breaking the others.
  • Never put a token in a shared document, a chat message or a code repository.
  • Revoke tokens that show as unused for a long time, and when someone leaves the team.
  • Things a token creates show mcp: and the token’s name as their creator, so a clear name tells you where they came from.

Something unclear or missing? Troubleshooting covers the common errors, or message us.

↑↓ to move↵ to openesc to close