Agent access
Agents act with a token you create in Workspace settings → Agents. Give each agent or machine its own token with only the access it needs. That way you can see who did what, and revoke one agent without touching the others. A token is shown once; only a hash of it is stored.
What a token can do
Section titled “What a token can do”When you create a token you choose:
- Access. Read and write works cards: claim, report progress, ask you, comment, complete, add and edit. It
can also create, rename and delete labels and create and edit epics without any extra permission.
Read-only can only look:
list_projects,get_board,get_card,get_card_activity,find_cardsandget_next_card. Everything else is refused and doesn’t appear in its tool list. - Extra permissions for a read-and-write token. By default only people delete cards or change the board’s
shape. Turn on Delete and restore cards or Manage lanes, swimlanes and flows to let the agent do that
too (reading flow rules with
get_flow_rulescomes with the second). Without them, those tools aren’t listed at all. - Projects. All projects, or one project. A limited token can’t see or change anything outside it.
- Expiry. 7 days to a year, or never. An expired token stops working on its own.
Read-only and per-project tokens are on Pro and up. Viewers can create read-only tokens on any plan. The Free plan allows 2 tokens, and no workspace holds more than 25 active tokens at once.
Some things are never available to agents, whatever the token: members and roles, tokens, invitations, projects, workspace settings, the audit log and exports.
Who can manage tokens
Section titled “Who can manage tokens”- Members and admins create tokens; viewers create read-only ones.
- The person who created a token, or any admin, can revoke it. It stops working at once.
- The token list shows each token’s access, projects, creator, last use and expiry.
- Creating and revoking tokens is recorded in the audit log.
When people change
Section titled “When people change”A token belongs to the person who made it:
- if they leave or are removed, their tokens stop working,
- if they become a viewer, their write tokens stop working (read-only ones keep going).
The same goes for runners: a runner stops working when its owner leaves, is removed or becomes a viewer.
So an agent never keeps more access than the person who connected it.
Workspace policies
Section titled “Workspace policies”On the Enterprise plan, admins set these under Workspace settings → Security → Agent access:
- Token lifetime. Tokens must expire within 7, 30, 90 or 180 days, or a year. A token created without an expiry gets the maximum. The cap applies to existing tokens too, counted from when each was created: one older than the new maximum stops working when you set it.
- Connector links. Each token also works as a private link (
/mcp/c/<token>) for apps that can only take a URL. The link contains the token, so it can end up in URLs and logs. Turn connector links off and tokens only work as anAuthorization: Bearerheader. See Connect over MCP.
If a token leaks
Section titled “If a token leaks”Revoke it in Workspace settings → Agents. The token and its private link stop working immediately. Then create a new one for the agent.