Operator tokens
Create named operator credentials for programmatic MCP and API access.
Operator tokens
An operator is a named machine identity owned by your account. Every programmatic request authenticates as an operator, so MCP calls and future API changes can be attributed to the specific tool or automation that made them. Use the web app with a normal session; use operator tokens for anything programmatic.
Operator tokens replace the retired personal account tokens (cet_…). Sending
a retired token to /mcp returns an actionable 401 pointing here.
Create an operator
- Open Account → Settings → Operators (
/account/settings/operators) and select New operator. - Choose a name (for example
Claude,n8n pipeline, orCI) and an optional description. - Pick the scope:
- All organizations I own — every organization where you currently have
the
ownerrole. - Specific organizations — only organizations you currently belong to.
- All organizations I own — every organization where you currently have
the
- Pick an expiration and optional label for the first key, then create the
operator. The plaintext key (
opt_…) is shown once; store it in your secret manager, then select Open operator to go to its page.
An operator never exceeds its scope, and membership and roles are re-checked on
every request. Removing yourself from an organization removes it from reachable
scope immediately; write operations require owner or admin.
Find your operators
The Operators list shows a summary of each operator: name, description, status
(Active or Suspended), scope, how many active keys it has (and how many
of those have expired), and when it was created. Select an operator to open its
page at /account/settings/operators/<id>, where you manage its keys, settings,
and activity.
Use a token
Send the token as a bearer credential:
Authorization: Bearer opt_your-tokenFor the MCP endpoint:
POST /mcp
Authorization: Bearer opt_your-token
Content-Type: application/json
Accept: application/json, text/event-streamSee Connect to MCP for the JSON-RPC flow. Agent-registered machine users can keep using Agent authentication.
Manage keys
An operator can hold several keys. Each key authenticates as the same operator, with the same scope, and can expire or be revoked independently. On the operator's page:
- Add a key: select Add key, pick an expiration and optional label. The plaintext key is shown once. Keys cannot be added while the operator is suspended.
- Rename a key: use the pencil action in the Active keys table to change or clear its label. The key itself does not change.
- Revoke a key: use the trash action and confirm. It stops authenticating immediately.
- Rotate: add a new key, switch your integration to it, then revoke the old key.
Expired keys stay in Active keys with an Expired badge until you revoke them. Revoked keys move to the collapsed Revoked keys history, which shows when each one was revoked.
Review activity
Recent activity on the operator's page lists the latest requests made with its keys: time, which key was used (label and prefix), the event and tool or method, status, duration, and any error. Use the key filter to show activity for a single key, including revoked ones, or All keys.
Change, suspend, or revoke an operator
From the operator's page:
- Edit: change the name, description, or scope. Changes apply immediately to every key.
- Suspend: pauses every key without losing the identity or its history; Resume at any time.
- Revoke: permanent. The operator and all of its keys stop authenticating, and you return to the Operators list.
Errors
| Status | Meaning |
|---|---|
401 invalid_token | Unknown, expired, revoked, suspended, or wrong-tenant credential; retired cet_… tokens also return 401 with migration guidance. |
403 | The operator has no reachable organization, or its role cannot perform the requested write. |
404 | The named organization is not reachable by this operator. |
Tokens are stored only as SHA-256 hashes; the plaintext is never recoverable after creation.