---
slug: scoped-personal-access-tokens-ga
published: 2026-10-06
change_type: new-feature
affected_products:
  - Platform
  - Security
  - CLI
  - AI
page: https://supabase.com/changelog/scoped-personal-access-tokens-ga
---

# Scoped personal access tokens are now generally available

Scoped personal access tokens (PATs) are now available to everyone. You can limit a token to specific projects or organizations and grant only the permissions it needs.

## You pick a token's access when you create it

On your [access tokens page](https://supabase.com/dashboard/account/tokens), choose:

- Resources: selected projects in one organization, or all projects in selected organizations.
- Permissions: read or read-write per capability, such as projects, database, auth, or storage.
- Expiry: a preset or a custom date up to one year out.

A review step shows the access you're granting and a risk level. You see the token value only when you create it.

You can't change a token's access later. To change it, delete the token and create a new one.

A token never has more access than you do. Every request checks your current role. When you lose access, so does the token.

## Scoped tokens work with the Management API, MCP server, and CLI

- Management API: all `/v1` and `/v2` endpoints. A 403 lists the permissions the token lacks in a `missing_permissions` array.
- Supabase MCP server: each tool checks the token's permissions. The token's detail view in the dashboard lists the tools it can call.
- Supabase CLI: pass the token with `supabase login --token` or set `SUPABASE_ACCESS_TOKEN`. The browser flow for `supabase login` still creates an account-level token. `supabase whoami` doesn't work with project- or organization-scoped tokens.

Some access needs a specific permission. Revealing secret API keys needs API Key Secrets. SQL runs read-only unless the token has Database read-write.

The [personal access tokens docs](https://supabase.com/docs/guides/platform/personal-access-tokens) map each permission to its endpoints and MCP tools.

## Your existing tokens keep working

We aren't revoking anything. Every existing token works until it expires or you delete it. You can still create an account-level token with "Create legacy token". A leaked scoped token exposes far less. GitHub secret scanning detects both kinds.

## Replace your account-level tokens with scoped ones

Swap each account-level token for a scoped token that has only the access its integration needs. If you're missing a permission or the form doesn't fit your workflow, tell us in the GitHub Discussion for this entry.
