# PipesHub Personal Access Tokens API

**Canonical:** https://apis.io/apis/pipeshub/pipeshub-personal-access-tokens-api/  
**Provider:** PipesHub — https://apis.io/providers/pipeshub/  
**Base URL:** https://app.pipeshub.com/api/v1  
**Documentation:** https://docs.pipeshub.com/developer/api-reference

PipesHub Personal Access Tokens API is one of 51 APIs that [PipesHub](https://apis.io/providers/pipeshub/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 6 JSON Schema definitions. Tagged areas include Personal Access Tokens. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and 6 JSON Schemas.

Self-service, long-lived, scoped, revocable credentials that act as their creator — unlike an OAuth app's `client_credentials` flow, which acts as the app. **Who can create one** - **Any authenticated org member** — unlike OAuth apps, this is deliberately not admin-gated. **Session only** - Every `/personal-access-tokens/*` route requires the user's interactive session JWT. OAuth access tokens and personal access tokens (`phpat_...`) are rejected with `403`. `scopes` is capped at the instance's `MCP_SCOPES`, not at the caller's own token, so a narrowly scoped token could otherwise mint itself a full-scope, non-expiring PAT. **How it's issued** - Minted through the same OAuth access-token machinery as `/oauth2/token`, against one lazily-created, per-org synthetic OAuth app (`clientId: pat-system:<orgId>`) that every PAT in that org shares. That app is hidden from `/oauth-clients/*` — it never appears in your own OAuth app list and can't be managed through those routes. - The raw token is prefixed `phpat_` ahead of the underlying JWT (see the `bearerAuth` security scheme) so it's recognizable to secret scanners. It's shown exactly once, at creation. **Expiry and scopes** - `expiryDays`: `30` (default), `90`, `365`, or `never`. - Scopes default to the org's full configured `MCP_SCOPES` set if none are requested; `GET /personal-access-tokens/scopes` lists what's available. **Admin visibility** - Regular members only ever see and revoke their own tokens. - Org admins can list and revoke *any* member's token via `/personal-access-tokens/admin*` — for incident response (a departed employee, a compromised laptop) — without needing the OAuth app CRUD access described above.

## Operations (6)

| Method | Path | Summary |
|---|---|---|
| GET | `/personal-access-tokens` | List your own personal access tokens |
| POST | `/personal-access-tokens` | Create a personal access token |
| GET | `/personal-access-tokens/scopes` | List scopes available for a new personal access token |
| DELETE | `/personal-access-tokens/{tokenId}` | Revoke one of your own personal access tokens |
| GET | `/personal-access-tokens/admin` | Admin: list every active personal access token in the org |
| DELETE | `/personal-access-tokens/admin/{tokenId}` | Admin: revoke any user's personal access token by id |

## Machine-readable artifacts (8)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/openapi/pipeshub-personal-access-tokens-api-openapi.yml
- **Documentation** — https://docs.pipeshub.com/developer/api-reference
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-get-record-by-id-response-schema-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-record-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-knowledge-hub-nodes-response-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-agent-create-conversation-request-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-conversation-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-create-conversation-request-schema.json

## Other PipesHub APIs (12)

- [PipesHub Agents API](https://apis.io/apis/pipeshub/pipeshub-agents-api/)
- [PipesHub AI Models Providers API](https://apis.io/apis/pipeshub/pipeshub-ai-models-providers-api/)
- [PipesHub Authentication Configuration API](https://apis.io/apis/pipeshub/pipeshub-authentication-configuration-api/)
- [PipesHub Configuration Manager API](https://apis.io/apis/pipeshub/pipeshub-configuration-manager-api/)
- [PipesHub Connector API](https://apis.io/apis/pipeshub/pipeshub-connector-api/)
- [PipesHub Connector Configuration API](https://apis.io/apis/pipeshub/pipeshub-connector-configuration-api/)
- [PipesHub Connector Control API](https://apis.io/apis/pipeshub/pipeshub-connector-control-api/)
- [PipesHub Connector Filters API](https://apis.io/apis/pipeshub/pipeshub-connector-filters-api/)
- [PipesHub Connector Instances API](https://apis.io/apis/pipeshub/pipeshub-connector-instances-api/)
- [PipesHub Connector OAuth API](https://apis.io/apis/pipeshub/pipeshub-connector-oauth-api/)
- [PipesHub Connector Registry API](https://apis.io/apis/pipeshub/pipeshub-connector-registry-api/)
- [PipesHub Connectors API](https://apis.io/apis/pipeshub/pipeshub-connectors-api/)

## Tags

Personal Access Tokens

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/pipeshub/pipeshub-personal-access-tokens-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/pipeshub/.
