---
id: pat-create
title: Create a personal access token
description: >-
  Creates a personal access token that acts as you. It either follows your
  access (`access: same_as_user`) or holds the grants you send (`access:
  grants`), and every check combines it with your access at that moment, so it
  can never do more than you.
sidebar_label: Create a personal access token
hide_title: true
hide_table_of_contents: true
api: >-
  eJztWt1uG8cVfpWDvYltrChKlu2UgAMojoKoQBxBkpGkkiAe7h5yJ9qdWc/MkmIF3vW+973qY7Sv0xfoKxRnZpbcJVcSbTd/RYNAJpezM+f3O39zF6VkEi1KK5SMBtEbTWjJAEJJ2iiJOWCSkDFg1Q1JsBlawMQaQANzVfXg2AIJm5GGscpzNXOPdf3Wk6H/MACDBV2jua4M6eFTUBoylacGbEYw0SitexEMybTxlv9l+DQGlCnQlPQckoySG0hUMRKSDAgLM2Gz1rFoPaWFKkjaGIziZQlKkLwHpAoKpYkXScfGpbyUX8C//vLPf//jr/Ds2VtlafDsGZx0CcEAaoICJU4obZytZhJyNRESDBkjlOzBIWh6X5GxgJXNSFqRoK1fQgmHJ8dwQ/P4XnkLmeRVSmkMwoCmnyhZvQ7Dg/7zYe9SRnGkStLIOjxOo0FUoh0kTpNRHFmcmGhwEXXzEl3FkaGk0sLOo8HFXTQi1KQPK5tFg4urxVUcBRa+VOk8GtxFiZKWpOWPWJY5cySU3P3JsAHdRSbJqED+ZOclRYNIjZjqyO8jNKVMjMSCaaPbUmgy12iZjlIzG1aQ4dfdktU2xmohJ1G8ZrCHsPw+JeB3YKy0syrHYOy+0i0WZU4wy0gTm4KupOk5AtwP0SDKVYL5jt/KRIsWbR1UjJUu+JcoRUs7Vjh22qSdZwTHZ9/tfP6yvwfvzt8ArzIWixLUmEmRKzLBWFUamCl9I+TEeVVRGQsjAuGXjStbaXJu4AybbQrmhBpwhvM2L/v9/Vc7/b2d/svzfn/g/v8Ts+Q138UOyapgvXh/i+Ko6a6sm5TGWOXM8HJJm9vvM+d0NT/sa6lyfrUDw5bzDxrLujAjMKz0BKX4s7OuODiCkBPQKiePFROyjCO5MgQ5WtI9OGP4kAqGATh67vjwpXmwBx8l87l7WC9ZYpCj/MgD2wzncTf2LPf7zNTUL/FgHYW8o66U1JLwIq7lulIOao3zDTmfBi/yBhSAcsjwUPPgsVIqC8jCrfGirYQeHDmGhKUCEtRaMOpLGEoth1DmFQuH2FCZR5Nh6X8PiOWBGSzekBnAkHVyLdIhq8N/MXk1GcZMH9PNRPFPQmakBcvZkxR+7WGaDh3VyyeaCjWl4X3A/KOqnIk5BXpaVnbBugUVgpUmoyqdsD05jnCkpgwBXkrhuNVrrHDyqmLRmC4gU5K+GzuwfBDiNG+yFEYHwGn5OL4xiLw9fVsrYsmNRzJ+FDTymXESYENAY8REUtoGhaY/vd4bYJKoStrXewMGTVNiQvx0heivD9gqV/RvRSqvXNLK5NS0gFVNagNIC8PMBSU73cIZEVycsi6vnuymKjG7HDqVDpTvOjU/de+7EC7kmGHmizXvKjDJhKRBIqLFIo6ssO6xdxHe/ox5WsRb61Ckv2cNirRBqJCWJqS7A9ZXvwX1ver3n++9evXiZbfujtMtNRfc+7+suWXKCk7YHAfUh2vKB2RP32Ogz5TUUNVUQ4FzSDDPfajx6ogdtqrKcjbEARMl0K0wtg6evUspqzwvc7ScxUCyzPmdykstpmip1jgfw/Fhzq/TLSbWh0yzpKil/w5gbmJsoqo8hYyhlymsIyRL2cVMysc+SitJhndtA3PsI1O9IASuFEbzBvyzULzdMg+NmFVj+xed8B6MYNHQ40Uzwx1owtRppszVnCN6nWNfbVrpYVDsdmZah8XfjJ2yFJZEPWacR03jMjErw4cBDcdfxVCQ5jpJSFYGGCEnOXVYmjCso96lPPbn8oZ2poJehXTB23MjjMtuXGLCCT8a/4N7JaMCDJWo0VI+H1xKYaHUKq0S8ikNbxjDLBPJNgmIM2Yu3QDTnyrDWRybeJ2c1xkW8+ZNjjDJIMiOUs9o2wxbvmozupSOC59aYuBxNG9kVSUaQ6YH58Ef66y5hmlXBNf6GgDKS+nZ8GkxYJp6GlcpXQGaKQ05rPMOpVqefLihJJTK5cM1IwlK1oOrUQK/m961kSwt/WwjHi2u2s6nSl9mTClnn4iuOhFz6Vdtq/xGzRxrlWQ5BNdo68W4UOvU6kNt2/cwTR+1/eDnXmnks04V6rtQD62fWWo1FSn14FtCU3EmjxMU0lj/yjwAaBsjQ6T9GNhKKScHUow8bNOPMnW8pLiGbrr1bQgYa1V4chzHPThic6+9oQHHjeJhTQB1eSLJI3VuVChzh+yFW/PYicObSHxcw9jCw7TrhjwWbnHCWAljIdNGzTiaB36D8TOscgHuYp2SCXXRvjTPtnHd0HwLYMeJA8UWZlvCgkUxxbzaokHCe7il7V3q6B8t2kIr0b6lWUPUjtozB7Oht+aiLD9dUuBbNWstlHYHpbsnsWpJtMvhZdcqCMozveS5Qb1T6ilhutPIOJSPFiGcdZGq6zd2NJVKfzi5yy5IXbZfhGB9X0zdbxWDg6igYuQxL2hAkymVNF7g+/09/mczzi8bfTBDA6Zy9IyrnLW7dWcO83yLAlZwthMadYHvoJd4xX5DaHHk/TD1X6oyrb9spDVblSPvpHhfuYqk1dFr2fHe/vODRbxlr5Dlt9EtnIgpyTrZ3Txgsy9YoLlhtkpxvZ0Tr1qR/tX2/oeHh4e3/N/JuXn9yU26dkeOXLh+uNv2ZHhfZ15Y43raoTv/pO4vPe092MfaHmHRGJWIVUN8pQE4Kko79y0uYSFD4wLGg/jaNF1WTI0WG8b3m4Lerft+3f1V+FppngS0dFibW6jSNK3mE0GXHS1WCNv7ZuWqlnC9f55kNAZAUkGu5IRbo0rfcMpPCVbGddY9IKRsRu5UpojzLOFS0inFEBDXa/ThTttHoEa7ieGzlKb4X7x89Tkjxq9SWO1/ckMmJJq97m7Jp/fruvZvpOAf1bNwQNuY9DlB5lMnthhKTYYtrnZ2jmshkPh0c9lDbreQPyoZfqiGZ2esp3CNPUdK5YRyM/XPZzg3MLS6oqELUfcM8Vqy5NWLOFIzSfpjjMC50yxTSxF1h62D/aApOXGY8NFHrRAnTH0Hbl66cVaOxvJJ6YfMy7gNhaNaLJ80P2OrYRq4VMlQcsfBqUTerwrO8V7u7PV3+p+f7+37HK/XD6OyX3P699gsb43IdAtj3cwFOKaG91sHjjE3bKGNXO4XEEDD6e/V0Qb7jQzzFyLRWVg4dls628XVacjyH+0M1vnlRvqydeL5I4dfSbN7UMn1etxw7W9/98O1M5yGVCFYJd8LoHzee/YsLF3mshzRU2HKHOeu61EXwPAt3hBwW4NTamOVH7cLya0/tx1wQu0TDhMuZYQmkiarBU0pDcPcjTS5x9k+x+8/9HGUpDRe/+5T6AVfWmiI/ESZhtgdzB/88MNmefUmFxyHSGulYVmNQVo5XoScYi64j1lWbuxcCMPNTOBWY0GWtPmgGuwh3RuLtjJvVOruSDA9URwVZAxOOvLZxurHIf6b8/MT8G9AolKWegjAoXsKpqREjEUCSVMeT6g36cVw0O/znz3+85z/HLSrgYN+n7GjTcu9VzfCkG6HozLHgXCWo8slmnxbZsLDo5A+GNJ8fWeMIq/0Wlo9wvQ6pKsOG53YtiBipAWNY8iqAuWKksaqOh564ni7WhqX0ZeYwqk/9DLiB+9kPe+i9DJaK5Uaq10lGTT6OJFpKvgj5pCSRZEbHmNXdkVW+5zzVebuYKvAnNHQZ+VsoSika8l7k25acN2NeNHlIWde/OseImTq7NzPmoQxFfnxux9UGe52/m+5hmkKIhjDC3aNF/19/vO8rfgXv55XMLNaYn7tF117kf1i/nEcjodgOke8xnsKPxEJwTuJUxQuD9xwmM7Xf1bXOZRQSbot/UU7z5JKkkpzngQnOaEhsHrum/Z1pFrUblOQzZS7gqeMK2CR79FFu6VriXkd+GZhpfNoEGXWlmawu4ul6DWHsr1EcXNzdTfvjL3DG3Xzht6Sfd6IT3DLGA3doigOH76uk6E/fn/uUhL2utPVxb6jWgA/SzN32x7pQzcZ1rqnjesd8afvytVRo4r+kA0btwy2rzUfPaE5FO6ahLXKcDeo6h76rGY+9wxMrj6k1c5EjZXrp5M23sH2ev1eP1olXIfN6x7squwJBcqGaflLxveVy+su3Lhx+v/ryb/T68kBpCzd2t0yR+EMwyHgXYDIC/6X7TVj4BxcRHd3IzT0TueLBT9+X5HmC8pXbJla+K7BBZtkRpiSbhjwG28uO+d86MqQN3IO9kL/xmGSUGkfXHvVwPaT787OGVnDhejCxfVI44zhBGfRIHI3spf+6Z7dRTnKSeWCVuT3ZBzGNoyvwXZzRoNy3qDw7s6vOGc9LBZRXHuvcyE3VfoPbgGV6A==
sidebar_class_name: post api-method
info_path: docs/api/authorization
custom_edit_url: null
canonical: 'https://docs.nullplatform.com/docs/api/pat-create'
---
<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"Create a personal access token"}
>
</Heading>

<MethodEndpoint
  method={"post"}
  path={"/pat"}
  context={"endpoint"}
>

</MethodEndpoint>

Creates a personal access token that acts as you. It either follows your access (`access: same_as_user`) or holds the grants you send (`access: grants`), and every check combines it with your access at that moment, so it can never do more than you.

> ℹ️ **Note:** Personal access tokens are managed with your own login session. A request authenticated with an API key, a personal access token included, is rejected with a `403`.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={undefined}
>

</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={{"content":{"application/json":{"schema":{"type":"object","required":["name","expires_at"],"properties":{"name":{"type":"string","description":"A descriptive name for the token, for example where it runs.","example":"local-scripts"},"expires_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token stops working. It must be in the future and at most a year away.","example":"2027-01-06T00:00:00Z"},"access":{"type":"string","enum":["grants","same_as_user"],"default":"grants","description":"What the token can do.\n\n- `same_as_user`: the token follows your access in the organization, including roles you get or lose later. Send no `grants`.\n- `grants`: the token holds only the `grants` you send.\n\nEither way, every check combines the token's access with yours at that moment.\n","example":"same_as_user"},"grants":{"type":"array","description":"Required when `access` is `grants`, and not allowed with `same_as_user`. Every item carries an `nrn` plus one of the shapes an API key grant takes: `role_id` or `role_slug`, `actions`, or `inherits` with `actions.add` and `actions.remove`.\n\n> ℹ️ **Note:** You can only grant roles you hold on that resource or one above it, and actions you hold there.\n","items":{"type":"object","oneOf":[{"type":"object","required":["nrn","role_slug"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the API key's role is assigned.","example":"organization=1:account=1:namespace=1:application=4"},"role_slug":{"type":"string","description":"The slug of the role assigned to the API key for this NRN.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n>\n","example":"machine:ci"}},"title":"grantsRoleSlug"},{"type":"object","required":["nrn","role_id"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource where the API key's role is assigned.","example":"organization=1:account=1:namespace=1:application=4"},"role_id":{"type":"integer","description":"The ID of the role assigned to the API key for this NRN.\n\n> Note: See [Roles](/docs/authorization/roles) for more info.\n>\n","example":700317756}},"title":"grantsRoleId"},{"type":"object","required":["nrn","actions"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=1:namespace=1"},"actions":{"type":"array","description":"The actions the API key may call at this NRN, without naming an existing role.\nnullplatform creates a role private to the key carrying exactly these actions.\n\n> Note: You can only grant actions you could hand out at that NRN yourself: the ones\n> you hold there, plus the ones carried by roles you may assign to an API key there.\n>\n","items":{"type":"string"},"example":["application:read","deployment:create"]}},"title":"grantsActions"},{"type":"object","required":["nrn","inherits"],"properties":{"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=1"},"inherits":{"type":"array","description":"Existing roles, by slug or ID, merged into a single role private to this key.\nInheriting two roles in one grant is not the same as granting them separately:\nit produces one role, which `actions.add` and `actions.remove` can then adjust.\nYou must be allowed to assign each inherited role to an API key at this NRN, the\nsame check a grant by `role_id` passes. The key follows the roles it inherits: an\naction later added to one of them reaches the key too.\n\n> Note: A role private to another API key cannot be inherited.\n>\n","items":{"oneOf":[{"type":"string"},{"type":"integer"}]},"example":["ops","developer"]},"actions":{"type":"object","description":"How the union of the inherited roles is adjusted.","properties":{"add":{"type":"array","description":"Actions granted on top of what the inherited roles provide. Measured against what you can hand out at this NRN.","items":{"type":"string"},"example":["application:delete"]},"remove":{"type":"array","description":"Inherited actions excluded from this grant. Each must be carried by one of the inherited roles, and none may also be in `add`.","items":{"type":"string"},"example":["deployment:create"]}}}},"title":"grantsInherits"}]}},"tags":{"type":"array","description":"Tags to find the token by. Each key can appear only once.","items":{"type":"object","properties":{"key":{"type":"string","description":"Tag key.","example":"team"},"value":{"type":"string","description":"Tag value.","example":"platform"}}}}},"title":"patNew"},"examples":{"Same access as you":{"value":{"name":"local-scripts","expires_at":"2027-01-06T00:00:00Z","access":"same_as_user","tags":[{"key":"team","value":"platform"}]}},"Read-only grant on one account":{"value":{"name":"read-only-reports","expires_at":"2027-01-06T00:00:00Z","access":"grants","grants":[{"nrn":"organization=1:account=2","role_slug":"member"}]}}}}}}}
>

</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"201":{"description":"The operation was successful.","content":{"application/json":{"schema":{"allOf":[{"type":"object","required":["id","name","access","tags","grants","expires_at","created_at","updated_at"],"properties":{"id":{"type":"integer","description":"Unique ID for the token.","example":1234},"name":{"type":"string","description":"The descriptive name given to the token.","example":"local-scripts"},"masked_api_key":{"type":"string","description":"The token, masked.","example":"AAAAxxxxxPTs="},"access":{"type":"string","enum":["grants","same_as_user"],"description":"Whether the token follows your access (`same_as_user`) or holds its own grants (`grants`).","example":"same_as_user"},"tags":{"type":"array","description":"Tags associated with the token. Empty when it has none.","items":{"type":"object","required":["key","value"],"properties":{"key":{"type":"string","description":"Tag key.","example":"team"},"value":{"type":"string","description":"Tag value.","example":"platform"}}}},"grants":{"type":"array","description":"What the token can do. For a `same_as_user` token, these are your own grants in the organization at the moment of the request. A token that no longer works, because it expired or your user is inactive, reports none.\n","items":{"type":"object","properties":{"id":{"type":"integer","description":"The ID of the grant.","example":5678},"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=2"},"role_id":{"type":"integer","description":"The ID of the role granted.","example":700317756},"role_slug":{"type":"string","description":"The slug of the role granted.","example":"developer"},"actions":{"type":"array","description":"The action names the grant resolves to, present when it was created from `actions` or `inherits`.","items":{"type":"string"},"example":["application:read","deployment:create"]}}}},"personal":{"type":"boolean","description":"Always `true` for a personal access token.","example":true},"owner_id":{"type":"integer","description":"The ID of the user who created the token.","example":42},"acting_user_id":{"type":"integer","description":"The ID of the user the token acts as: you.","example":42},"last_used_at":{"type":"string","format":"date-time","nullable":true,"description":"The ISO-8601 UTC timestamp of when the token was last exchanged for an access token.","example":"2026-10-08T12:00:00.000Z"},"expires_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token stops working.","example":"2027-01-06T00:00:00.000Z"},"expired":{"type":"boolean","description":"Whether the token has expired.","example":false},"created_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was created.","example":"2026-10-08T00:00:00.000Z"},"updated_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was last updated.","example":"2026-10-08T00:00:00.000Z"}},"title":"patResponse"},{"type":"object","required":["api_key"],"properties":{"api_key":{"type":"string","description":"Your new personal access token.\n\n>\n> ⚠️ **Save your token securely.**\n>\n> The token is displayed only once. Make sure to store it in a secure location as it cannot be retrieved later.","example":"AAAA.1234567890abcdef1234567890abcdefPTs="}}}],"title":"patPostResponse"}}}},"4XX":{"description":"Client error responses due to invalid input or missing parameters.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific client error (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"bad_request"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Bad Request\", \"Unauthorized\").","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error (e.g., 500, 502, 503).","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Internal Server Error\", \"Service Unavailable\").","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred. Please try again later."}}}}}}}}
>

</StatusCodes>

