API tokens
Create, use and revoke the API tokens that let AI assistants reach your data. Each token belongs to one organization and is shown only once.
An API token lets an AI assistant, like Claude or ChatGPT, reach your organization’s data through Orcabase’s MCP server. Each token belongs to one organization and can only ever see that organization.
Create a token
- Go to Settings then API Tokens then New token.
- Name it after where it’ll be used, like “Claude, Jane’s laptop”, and click Create token.
- Click Copy token and paste it into your assistant. See Set up Claude and ChatGPT.
You’ll only see it once
Orcabase stores a scrambled version of the token that it can check, not the token itself, so it can’t show it again. If you lose it, revoke it and make a new one.
The token list
| Column | Shows |
|---|---|
| Name | The name you gave it. |
| Status | Active, or Revoked. |
| Created | When it was made. |
| Last used | When an assistant last used it, or Never. A quick way to spot tokens nobody needs. |
Revoke a token
Click Revoke token next to it. It stops working on the very next request, with nothing to wait for. Things created with it stay.
Good habits
- One token per person and per device, so you can revoke one without breaking the others.
- Never put a token in a shared document, a chat message or a code repository.
- Revoke tokens that show as unused for a long time, and when someone leaves the team.
- Things a token creates show
mcp:and the token’s name as their creator, so a clear name tells you where they came from.
Something unclear or missing? Troubleshooting covers the common errors, or message us.