# Personal access tokens

A personal access token is a personal access key that connects external tools to
Lalabase — for example an MCP server, so an AI assistant like Claude Code can read
and act on your projects and tickets directly. The token talks to the same API/MCP
interface as the app and honours the same permissions.

## Creating a token

1. Open **API Tokens** from the account menu and click **Create token**.
2. Give it a **name** that reminds you of its purpose later
   (e.g. "Claude Code – Client XY").
3. Set the **validity** (default: 30 days, one year at most).
4. Choose the **organisations** the token may reach — per organisation either all
   projects (including future ones) or only selected ones.
5. Create the token and **copy it straight away**: it is shown only once.

<div class="docs-callout docs-callout--warning">
  <div class="docs-callout__title">A token is like a password</div>
  <p>By default a token is limited to <strong>read-only</strong>. Write access (creating tickets and comments, booking time on tickets, marking your inbox entries as read) is a deliberate opt-in that you grant by unchecking "Read-only access". Keep the token safe and revoke it from the overview as soon as you no longer need it.</p>
</div>

A token controls access *into* Lalabase from outside. Which AI provider Lalabase
itself uses is set separately under
[Using your own AI API keys](https://lalabase.com/docs/en/guides/ai/byok).
