| 1 | 1 | | --- |
| 2 | 2 | | title: Accounts and authentication |
| 3 | | − | description: Accounts, invites, email addresses, confirming them, personal access tokens and their scopes, OAuth, signing in from a tool, password reset and your security log. |
| 3 | + | description: Accounts, invites, email addresses, confirming them, fine-grained and classic personal access tokens, scopes and permissions, a workspace's rules for tokens, OAuth, signing in from a tool, password reset and your security log. |
| 4 | 4 | | --- |
| 5 | 5 | | |
| 6 | 6 | | ## Creating an account |
| ⋯ |
| 27 | 27 | | | Emails | [`/settings/emails`](https://g1t.sh/settings/emails) | Your [email addresses](#email-addresses), the backup address, and [keeping your address private](#keeping-your-address-private). | |
| 28 | 28 | | | Invites | [`/settings/invites`](https://g1t.sh/settings/invites) | [Making, copying and revoking invites](#invites). | |
| 29 | 29 | | | SSH keys | [`/settings/keys`](https://g1t.sh/settings/keys) | Public keys for [git over SSH](/guides/git/#ssh), each with when it was added and last used. | |
| 30 | | − | | Access tokens | [`/settings/tokens`](https://g1t.sh/settings/tokens) | Your [personal access tokens](#access-tokens). | |
| 30 | + | | Access tokens | [`/settings/tokens`](https://g1t.sh/settings/tokens) | Your [personal access tokens](#access-tokens): fine-grained and classic. | |
| 31 | 31 | | | GitHub | [`/settings/github`](https://g1t.sh/settings/github) | [Linking and unlinking GitHub](/guides/github/#link-and-unlink-github). | |
| 32 | 32 | | | Connected applications | [`/settings/applications`](https://g1t.sh/settings/applications) | Tools you [signed in to with OAuth](#signing-in-with-oauth), such as an agent using the MCP server. | |
| 33 | 33 | | | Security log | [`/settings/security-log`](https://g1t.sh/settings/security-log) | [What happened to your account](#security-log). | |
| ⋯ |
| 278 | 278 | | If you lose one, delete it and create another. Delete a token the moment |
| 279 | 279 | | you think someone else has seen it. |
| 280 | 280 | | |
| 281 | | − | A token reaches everything you can reach, and its [scopes](#scopes) say |
| 282 | | − | what it may do there. Give each token only the scopes the thing using it |
| 283 | | − | needs. |
| 281 | + | There are two kinds of personal access token, on two tabs of |
| 282 | + | [Settings → Access tokens](https://g1t.sh/settings/tokens): |
| 283 | + | |
| 284 | + | | | Fine-grained token | Classic token | |
| 285 | + | | --- | --- | --- | |
| 286 | + | | Reaches | One resource owner: one workspace you belong to, or your own account | Every workspace and repository you can reach, including ones you join later | |
| 287 | + | | Repositories | All of the workspace's, the ones you choose (up to 50), or public ones only | All you can reach | |
| 288 | + | | What it may do | A level for each [permission](#permissions) | Its [scopes](#scopes) | |
| 289 | + | | Expires | Always, within 366 days | 7 days to 1 year, or never | |
| 290 | + | | A workspace can | Require an owner's approval first, or keep them out | Keep them out | |
| 291 | + | |
| 292 | + | Both never do more than you could on the website, and both are sent the |
| 293 | + | same way. Prefer a fine-grained token: it reaches only what it needs. |
| 284 | 294 | | |
| 285 | 295 | | For CI and integrations that work for a team, a workspace can have tokens |
| 286 | 296 | | of its own that act as the workspace and keep working when their creator |
| 287 | 297 | | leaves. See [workspace tokens](#workspace-tokens). |
| 288 | 298 | | |
| 289 | | − | ### Create a token |
| 299 | + | ### Create a fine-grained token |
| 300 | + | |
| 301 | + | 1. Open [Settings → Access tokens](https://g1t.sh/settings/tokens). The |
| 302 | + | **Fine-grained tokens** tab is first. |
| 303 | + | 2. Under **New fine-grained token**, give it a **Token name** after what |
| 304 | + | will use it, and optionally a **Description**, which a workspace's |
| 305 | + | owners see if they review it. |
| 306 | + | 3. Choose the **Resource owner**: a workspace you belong to, or **Your |
| 307 | + | account**. A workspace that does not allow fine-grained tokens cannot be |
| 308 | + | chosen. |
| 309 | + | 4. Choose its **Expiration**: 7, 30, 60, 90 or 180 days, or 1 year, or |
| 310 | + | less when the workspace sets a shorter limit. |
| 311 | + | 5. Under **Repository access**, choose **Public repositories** (read-only), |
| 312 | + | **All repositories** of the workspace (including ones made later), or |
| 313 | + | **Only select repositories**, and tick up to 50. |
| 314 | + | 6. Under **Permissions**, set each one the token needs to **Read-only** or |
| 315 | + | **Read and write** (and **Admin** for packages). **Metadata** is always |
| 316 | + | read-only. Each row shows the g1t scopes its level gives. |
| 317 | + | 7. Select **Generate token**, and copy it. It is not shown again. |
| 318 | + | |
| 319 | + | When the workspace [requires approval](#a-workspaces-rules-for-tokens) and |
| 320 | + | you are not one of its owners, the token is made **Pending approval**: it |
| 321 | + | works at once, but reads public repositories only until an owner approves |
| 322 | + | it. The owners hear of it in their [inbox](/guides/inbox/), and you hear of |
| 323 | + | their answer in yours. An owner's own token never waits. |
| 324 | + | |
| 325 | + | Select **Edit** on a token to change its name, description, repositories |
| 326 | + | or permissions. The token stays the same. Widening it in a workspace that |
| 327 | + | requires approval asks again. Its resource owner and expiry cannot change; |
| 328 | + | make a new token instead. |
| 329 | + | |
| 330 | + | The list shows each token's status (pending, denied or revoked, with the |
| 331 | + | owner's note), what it reaches, its permissions, and when it was made, last |
| 332 | + | used and expires. |
| 333 | + | |
| 334 | + | ### Permissions |
| 335 | + | |
| 336 | + | Each level of a fine-grained token's permissions gives g1t |
| 337 | + | [scopes](#scopes), and the token is checked by those scopes |
| 338 | + | exactly as a classic token is. Where two permissions give the same scopes |
| 339 | + | (Checks and Commit statuses; Secrets and Variables; Deployments and Pages), |
| 340 | + | giving either gives both. |
| 290 | 341 | | |
| 291 | | − | 1. Open [Settings → Access tokens](https://g1t.sh/settings/tokens). |
| 292 | | − | 2. Under **New token**, give it a **Name** after what will use it. |
| 342 | + | Repository permissions, for a workspace as the resource owner: |
| 343 | + | |
| 344 | + | | Permission | Levels | What it covers | g1t scopes it gives | |
| 345 | + | | --- | --- | --- | --- | |
| 346 | + | | `actions` (Actions) | read, write | Workflow runs, jobs, logs and artifacts: reading them, and running, cancelling and rerunning workflows | read: `workflows:read`; write: `workflows:write` | |
| 347 | + | | `administration` (Administration) | read, write | Repository settings, rulesets, who has access and deploy keys; renaming, archiving, transferring and deleting | read: `repo:read`, `access:read`; write: `repo:admin`, `access:admin` | |
| 348 | + | | `agents` (g1t agents) | write | Putting g1t's agents to work and messaging them, which uses the workspace's money | write: `agents:run` | |
| 349 | + | | `checks` (Checks) | read, write | Check runs and check suites on commits. Shares its scopes with Commit statuses | read: `checks:read`; write: `checks:write` | |
| 350 | + | | `contents` (Contents) | read, write | Code, branches, commits and releases: cloning and fetching, pushing, and publishing releases | read: `code:read`; write: `code:write`, `repo:write` | |
| 351 | + | | `deployments` (Deployments) | read, write | Deployments and their statuses | read: `deployments:read`; write: `deployments:write` | |
| 352 | + | | `environments` (Environments) | read, write | Environments, and their secrets and variables | read: `deployments:read`, `secrets:read`; write: `secrets:admin` | |
| 353 | + | | `issues` (Issues) | read, write | Issues, their comments, labels and milestones, and plans | read: `issues:read`; write: `issues:write` | |
| 354 | + | | `memory` (Memory and context) | read, write | Recalling memory and searching the workspace's context, and saving memory for the next agent | read: `memory:read`; write: `memory:write` | |
| 355 | + | | `metadata` (Metadata) | read | Seeing repositories and searching them. Always read | read: `repo:read` | |
| 356 | + | | `packages` (Packages) | read, write, admin | Pulling private packages, publishing them, and (admin) deleting packages and versions | read: `packages:read`; write: `packages:write`; admin: `packages:delete` | |
| 357 | + | | `pages` (Pages) | read, write | Deployments on g1t.page. Shares its scopes with Deployments | read: `deployments:read`; write: `deployments:write` | |
| 358 | + | | `pull_requests` (Pull requests) | read, write | Pull requests, their reviews, changes, sessions and merge queues | read: `pull_requests:read`; write: `pull_requests:write` | |
| 359 | + | | `secrets` (Secrets) | read, write | Actions secrets: listing them (never their values), setting and deleting them. Shares its scopes with Variables | read: `secrets:read`; write: `secrets:admin` | |
| 360 | + | | `security_events` (Security events and alerts) | read, write | Code scanning, secret scanning and vulnerability alerts, SARIF uploads and security settings | read: `security:read`; write: `security:write` | |
| 361 | + | | `statuses` (Commit statuses) | read, write | Statuses on commits. Shares its scopes with Checks | read: `checks:read`; write: `checks:write` | |
| 362 | + | | `variables` (Variables) | read, write | Actions variables: reading, setting and deleting them. Shares its scopes with Secrets | read: `secrets:read`; write: `secrets:admin` | |
| 363 | + | | `webhooks` (Webhooks) | read, write | Webhooks and their deliveries | read: `webhooks:read`; write: `webhooks:admin` | |
| 364 | + | | `workflows` (Workflows) | write | Adding, changing and deleting workflow files under .g1t/workflows and .github/workflows. Write only | write: `workflow_files:write` | |
| 365 | + | |
| 366 | + | Workspace permissions, for a workspace as the resource owner: |
| 367 | + | |
| 368 | + | | Permission | Levels | What it covers | g1t scopes it gives | |
| 369 | + | | --- | --- | --- | --- | |
| 370 | + | | `members` (Members) | read, write | The workspace's people, invitations and teams | read: `workspace:read`; write: `workspace:admin` | |
| 371 | + | | `workspace_administration` (Administration) | read, write | The workspace's settings, integrations, rulesets and base permission | read: `workspace:read`, `access:read`; write: `workspace:admin`, `access:admin` | |
| 372 | + | | `workspace_billing` (Billing) | read, write | Usage, budget, AI credit and invoices, and (write) changing the budget and buying credit | read: `billing:read`; write: `billing:write` | |
| 373 | + | | `models` (AI Gateway) | read, write | AI Gateway requests: seeing them, and sending requests, which uses the workspace's AI credit | read: `models:read`; write: `models:write` | |
| 374 | + | | `self_hosted_runners` (Self-hosted runners) | read, write | Runners, their groups and settings | read: `runners:read`; write: `runners:admin` | |
| 375 | + | | `workspace_secrets` (Secrets) | read, write | The workspace's Actions secrets. Shares its scopes with the repository Secrets permission | read: `secrets:read`; write: `secrets:admin` | |
| 376 | + | | `workspace_webhooks` (Webhooks) | read, write | The workspace's webhooks. Shares its scopes with the repository Webhooks permission | read: `webhooks:read`; write: `webhooks:admin` | |
| 377 | + | |
| 378 | + | Account permissions, for your own account as the resource owner: |
| 379 | + | |
| 380 | + | | Permission | Levels | What it covers | g1t scopes it gives | |
| 381 | + | | --- | --- | --- | --- | |
| 382 | + | | `email_addresses` (Email addresses) | read, write | Your email addresses and email settings, invites and invitations | read: `account:read`; write: `account:write` | |
| 383 | + | | `starring` (Starring) | read, write | Stars and pinned projects. Shares its scopes with Email addresses | read: `account:read`; write: `account:write` | |
| 384 | + | | `notifications` (Notifications) | read, write | Your inbox, subscriptions and watched repositories | read: `notifications:read`; write: `notifications:write` | |
| 385 | + | |
| 386 | + | ### What a fine-grained token reaches |
| 387 | + | |
| 388 | + | - **In its workspace**, what your role allows, in the repositories it |
| 389 | + | reaches, and only what its permissions give. |
| 390 | + | - **Elsewhere**, public repositories, read-only, as anyone can. It cannot |
| 391 | + | comment, open issues or push there. |
| 392 | + | - **With your account as its resource owner**, public repositories, |
| 393 | + | read-only, and what its account permissions give. |
| 394 | + | - **While pending, denied or revoked**, public repositories, read-only. |
| 395 | + | |
| 396 | + | A request it cannot make answers `403` naming why: the scope it lacks, or |
| 397 | + | `This fine-grained token's resource owner is the workspace acme: it can only |
| 398 | + | read public repositories elsewhere, …`. A repository outside its selection |
| 399 | + | answers as if it did not exist. |
| 400 | + | |
| 401 | + | ### Create a classic token |
| 402 | + | |
| 403 | + | 1. Open [Settings → Access tokens](https://g1t.sh/settings/tokens), and |
| 404 | + | select the **Tokens (classic)** tab. |
| 405 | + | 2. Under **New classic token**, give it a **Name** after what will use it. |
| 293 | 406 | | 3. Choose when it **Expires**: 7 days, 30 days, 90 days (the default), |
| 294 | 407 | | 1 year, or No expiry. An expired token stops working; make a new one. |
| 295 | 408 | | No expiry shows a warning: the token works until someone deletes it. |
| ⋯ |
| 304 | 417 | | and select **Save access**. The token stays the same; the change applies |
| 305 | 418 | | from its next request. |
| 306 | 419 | | |
| 420 | + | A classic token reaches every workspace you belong to unless the |
| 421 | + | workspace's [rules](#a-workspaces-rules-for-tokens) keep it out: one that |
| 422 | + | does not allow classic tokens, one whose longest lifetime this token |
| 423 | + | exceeds, or one whose owner revoked it there. It keeps working everywhere |
| 424 | + | else. |
| 425 | + | |
| 307 | 426 | | ## Scopes |
| 308 | 427 | | |
| 309 | 428 | | A scope is a resource and a level, written `resource:level`, such as |
| ⋯ |
| 320 | 439 | | | Packages | `packages:read`, `packages:write` | |
| 321 | 440 | | | Issues & pull requests | `issues:read`, `issues:write`, `pull_requests:read`, `pull_requests:write` | |
| 322 | 441 | | | Agents | `agents:run` | |
| 323 | | − | | Workflows | `workflows:read`, `workflows:write` | |
| 442 | + | | Workflows | `workflows:read`, `workflows:write`, `workflow_files:write` | |
| 324 | 443 | | | Checks | `checks:read`, `checks:write` | |
| 325 | 444 | | | Deployments | `deployments:read`, `deployments:write` | |
| 326 | 445 | | | Memory & search | `memory:read`, `memory:write` | |
| ⋯ |
| 356 | 475 | | | `agents:run` | Put g1t to work and message it, which uses the workspace's money | |
| 357 | 476 | | | `workflows:read` | Read workflows, runs and logs | |
| 358 | 477 | | | `workflows:write` | Run, cancel, rerun and turn workflows on or off | |
| 478 | + | | `workflow_files:write` | Add, change and delete [workflow files](#workflow-files) under `.g1t/workflows` and `.github/workflows`, with git or the API. Not in any preset but full access. | |
| 359 | 479 | | | `checks:read` | Read commits' statuses, check runs, check suites and annotations | |
| 360 | 480 | | | `checks:write` | Report [statuses and check runs](/guides/checks/) on commits, and ask for checks to run again | |
| 361 | 481 | | | `deployments:read` | See [deployments](/guides/deployments-api/), their statuses and environments | |
| ⋯ |
| 395 | 515 | | |
| 396 | 516 | | ### What a token can do |
| 397 | 517 | | |
| 398 | | − | What a request may do is where two things overlap: |
| 518 | + | What a request may do is where these overlap: |
| 399 | 519 | | |
| 400 | | − | 1. **Your role.** A token reaches every workspace and repository you can, |
| 401 | | − | including ones you join later, and never does more there than you could |
| 402 | | − | on the website. A token with `repo:admin` still cannot delete a |
| 403 | | − | repository unless you are an owner of its workspace. See |
| 404 | | − | [access and roles](/guides/access-and-roles/). |
| 405 | | − | 2. **Its scopes.** What kinds of thing it may do. |
| 520 | + | 1. **Your role.** A token never does more than you could on the website. A |
| 521 | + | token with `repo:admin` still cannot delete a repository unless you are |
| 522 | + | an owner of its workspace. See [access and roles](/guides/access-and-roles/). |
| 523 | + | 2. **What it reaches.** A classic token, every workspace and repository you |
| 524 | + | can reach, including ones you join later, unless a workspace's |
| 525 | + | [rules](#a-workspaces-rules-for-tokens) keep it out. A fine-grained |
| 526 | + | token, its [resource owner](#what-a-fine-grained-token-reaches) only. |
| 527 | + | 3. **Its scopes.** What kinds of thing it may do: chosen directly on a |
| 528 | + | classic token, given by its permissions on a fine-grained one. |
| 406 | 529 | | |
| 407 | | − | To keep a token away from a workspace, use a |
| 408 | | − | [workspace token](#workspace-tokens) instead: it reaches only its own |
| 409 | | − | workspace. |
| 530 | + | To keep a token away from other workspaces, make a fine-grained one, or use |
| 531 | + | a [workspace token](#workspace-tokens): it reaches only its own workspace. |
| 410 | 532 | | |
| 411 | 533 | | ### Presets |
| 412 | 534 | | |
| ⋯ |
| 433 | 555 | | | Clone or fetch a public repository | No scope | |
| 434 | 556 | | | Clone or fetch a private repository | `code:read` | |
| 435 | 557 | | | Push | `code:write` | |
| 558 | + | | Push commits that add, change or delete [workflow files](#workflow-files) | `code:write` and `workflow_files:write` | |
| 436 | 559 | | |
| 437 | 560 | | Your role on the repository applies too, as on the website. A refused push |
| 438 | 561 | | or clone says which scope is missing. |
| 439 | 562 | | |
| 563 | + | ### Workflow files |
| 564 | + | |
| 565 | + | A workflow runs with its repository's secrets and a token of its own, so |
| 566 | + | changing one is as powerful as holding those. A token therefore needs |
| 567 | + | `workflow_files:write` (a fine-grained token's **Workflows** permission) to |
| 568 | + | add, change or delete any file under `.g1t/workflows/` or |
| 569 | + | `.github/workflows/`, besides `code:write`: |
| 570 | + | |
| 571 | + | - **With git**, every commit a push adds is compared with its parent, and a |
| 572 | + | push that changes a workflow file is declined, naming it: |
| 573 | + | |
| 574 | + | ```text |
| 575 | + | remote: This access token cannot change the workflow file .github/workflows/ci.yml: it needs the workflow_files:write scope. |
| 576 | + | remote: Push with a token that has the workflow_files:write scope, or make the change signed in on g1t.sh. |
| 577 | + | ``` |
| 578 | + | |
| 579 | + | A push too large for g1t to read whole is declined for such a token too, |
| 580 | + | since it cannot be checked; push it in smaller parts. |
| 581 | + | - **Through g1t**, a file written for a token (such as a starter workflow) |
| 582 | + | is refused the same way. |
| 583 | + | - **A workflow job's token** never may, whatever its `permissions:` say. |
| 584 | + | See [the job's token](/guides/actions/#the-jobs-token). |
| 585 | + | - **Signed in on g1t.sh**, your role decides, as for any file. |
| 586 | + | |
| 587 | + | Full-access tokens, and tokens made before scopes, include it. A |
| 588 | + | [deploy key](/guides/git/#deploy-keys) with write access may change |
| 589 | + | workflow files. |
| 590 | + | |
| 440 | 591 | | ### When a token lacks a scope |
| 441 | 592 | | |
| 442 | 593 | | The API answers `403` with the scope that was missing in `needed_scope`: |
| ⋯ |
| 473 | 624 | | owner makes them in the workspace's **Settings → Access tokens**, with the |
| 474 | 625 | | same checklist and expiry choices; the form starts on the CI preset. A |
| 475 | 626 | | workspace token reaches all of that workspace's repositories, never |
| 476 | | − | another workspace, and cannot manage people, tokens or workspaces. See |
| 627 | + | another workspace, and cannot manage people, tokens or workspaces. |
| 628 | + | |
| 629 | + | It has the Write role on the workspace's repositories, as a member does: |
| 630 | + | it pushes, merges and works on issues and pull requests, within its scopes. |
| 631 | + | Tick **Admin on the workspace's repositories** when making it to give it |
| 632 | + | Admin instead, so it can also manage webhooks, secrets, deploy keys and who |
| 633 | + | has access, and manage teams as an owner would. Only an owner can, and only |
| 634 | + | when making it. See |
| 477 | 635 | | [workspace access tokens](/guides/workspaces/#workspace-access-tokens). |
| 478 | 636 | | |
| 637 | + | ## A workspace's rules for tokens |
| 638 | + | |
| 639 | + | An owner decides which of the members' own personal tokens reach the |
| 640 | + | workspace, under its **Settings → Personal access tokens** |
| 641 | + | (`g1t.sh/<workspace>/-/personal-access-tokens`). The rules apply from each |
| 642 | + | token's next request, to tokens made before them too. A token they keep out |
| 643 | + | keeps working everywhere else, and reads the workspace's public |
| 644 | + | repositories as anyone can. |
| 645 | + | |
| 646 | + | | Rule | Default | What it does | |
| 647 | + | | --- | --- | --- | |
| 648 | + | | Allow fine-grained personal access tokens | On | Off: no fine-grained token can name the workspace as its resource owner, and existing ones stop reaching it. | |
| 649 | + | | Require approval of fine-grained tokens | On | A member's fine-grained token naming the workspace waits for an owner's approval, and again when it is widened. Owners' own tokens never wait. | |
| 650 | + | | Allow classic personal access tokens | On | Off: classic tokens no longer reach the workspace. | |
| 651 | + | | Tokens must expire | Off | On: a token that never expires does not reach the workspace. | |
| 652 | + | | Longest lifetime | No limit | A token that lasts longer (from when it was made to when it expires), or never expires, does not reach the workspace. Fine-grained tokens for it cannot be made longer. | |
| 653 | + | |
| 654 | + | The same page lists: |
| 655 | + | |
| 656 | + | - **Waiting for approval.** Each pending fine-grained token with its owner, |
| 657 | + | permissions, repositories and expiry. Add an optional note, then select |
| 658 | + | **Approve** or **Deny**. Its owner hears of it in their inbox, with the |
| 659 | + | note. |
| 660 | + | - **Tokens that can reach the workspace.** Every fine-grained token naming |
| 661 | + | it, and every classic token of its members and outside collaborators that |
| 662 | + | has not expired, with its owner, permissions or scopes, last use and |
| 663 | + | expiry, and whether it reaches the workspace now (and if not, why). Never |
| 664 | + | the token itself. Select **Revoke** to take one out: a fine-grained token |
| 665 | + | stops reaching the workspace for good; a classic token keeps working |
| 666 | + | everywhere else, but never reaches this workspace again. |
| 667 | + | |
| 668 | + | Approvals, denials, revocations and rule changes are |
| 669 | + | [audit log](/guides/audit-log/) entries: `token.approval_requested`, |
| 670 | + | `token.approved`, `token.denied`, `token.revoked` and |
| 671 | + | `token.policy_changed`. |
| 672 | + | |
| 673 | + | ### A workspace's rules through the API |
| 674 | + | |
| 675 | + | Owners, as people (a personal token with the scope works; a workspace's own |
| 676 | + | token does not): |
| 677 | + | |
| 678 | + | | Route | MCP tool and action | What it does | Scope | |
| 679 | + | | --- | --- | --- | --- | |
| 680 | + | | [`GET /workspaces/{workspace}/personal-access-token-policy`](/reference/api/personal-access-tokens/get-token-policy/) | `workspace` `get_token_policy` | The rules. Members may read them. | `workspace:read` | |
| 681 | + | | [`PATCH /workspaces/{workspace}/personal-access-token-policy`](/reference/api/personal-access-tokens/set-token-policy/) | `workspace` `set_token_policy` | Change `allow_classic`, `allow_fine_grained`, `require_approval`, `max_lifetime_days` (0 for no limit) or `forbid_no_expiry` | `workspace:admin` | |
| 682 | + | | [`GET /workspaces/{workspace}/personal-access-tokens`](/reference/api/personal-access-tokens/list-member-tokens/) | `workspace` `list_member_tokens` | The tokens that can reach it; `kind` is `classic` or `fine_grained` | `access:read` | |
| 683 | + | | [`GET /workspaces/{workspace}/personal-access-token-requests`](/reference/api/personal-access-tokens/list-token-requests/) | `workspace` `list_token_requests` | The fine-grained tokens waiting for approval | `access:read` | |
| 684 | + | | [`POST /workspaces/{workspace}/personal-access-token-requests/{id}`](/reference/api/personal-access-tokens/review-token-request/) | `workspace` `review_token_request` | `decision` is `approve` or `deny`, with an optional `reason` | `access:admin` | |
| 685 | + | | [`POST /workspaces/{workspace}/personal-access-tokens/{id}`](/reference/api/personal-access-tokens/revoke-member-token/) | `workspace` `revoke_member_token` | Revoke a token in the workspace, with an optional `reason` | `access:admin` | |
| 686 | + | |
| 479 | 687 | | ## Signing in with OAuth |
| 480 | 688 | | |
| 481 | 689 | | Applications that can open your browser, such as an agent connecting to the |
| ⋯ |
| 562 | 770 | | |
| 563 | 771 | | Only approve a code you asked for. The token has full access: it can do |
| 564 | 772 | | everything you can. To give a tool less, make an |
| 565 | | − | [access token](#create-a-token) with only the scopes it needs instead. |
| 773 | + | [access token](#create-a-fine-grained-token) with only the scopes it needs instead. |
| 566 | 774 | | |
| 567 | 775 | | ## Resetting your password |
| 568 | 776 | | |