Scoped personal access tokens are now generally available

Oct 6, 2026

Scoped personal access tokens (PATs) are now available to everyone. You can limit a token to specific projects or organizations and grant only the permissions it needs.

You pick a token's access when you create it#

On your access tokens page, choose:

  • Resources: selected projects in one organization, or all projects in selected organizations.
  • Permissions: read or read-write per capability, such as projects, database, auth, or storage.
  • Expiry: a preset or a custom date up to one year out.

A review step shows the access you're granting and a risk level. You see the token value only when you create it.

You can't change a token's access later. To change it, delete the token and create a new one.

A token never has more access than you do. Every request checks your current role. When you lose access, so does the token.

Scoped tokens work with the Management API, MCP server, and CLI#

  • Management API: all /v1 and /v2 endpoints. A 403 lists the permissions the token lacks in a missing_permissions array.
  • Supabase MCP server: each tool checks the token's permissions. The token's detail view in the dashboard lists the tools it can call.
  • Supabase CLI: pass the token with supabase login --token or set SUPABASE_ACCESS_TOKEN. The browser flow for supabase login still creates an account-level token. supabase whoami doesn't work with project- or organization-scoped tokens.

Some access needs a specific permission. Revealing secret API keys needs API Key Secrets. SQL runs read-only unless the token has Database read-write.

The personal access tokens docs map each permission to its endpoints and MCP tools.

Your existing tokens keep working#

We aren't revoking anything. Every existing token works until it expires or you delete it. You can still create an account-level token with "Create legacy token". A leaked scoped token exposes far less. GitHub secret scanning detects both kinds.

Replace your account-level tokens with scoped ones#

Swap each account-level token for a scoped token that has only the access its integration needs. If you're missing a permission or the form doesn't fit your workflow, tell us in the GitHub Discussion for this entry.

Build in a weekend, scale to millions