Version
READ

list_tokens

List the authenticated user's own personal access tokens with abilities and scope tuples split out.

List the authenticated user's own personal access tokens with abilities and scope tuples split out. scope:team:... and scope:project:... entries are peeled off the raw abilities array into a structured scopes object for readability. The plaintext token value is never surfaced — minting happens in the dashboard.

Requires ability

The token behind the MCP session must hold it, or the call is refused with TOKEN_MISSING_ABILITY.

Runs the same action as

The REST endpoint and this tool share one action, so validation, permissions and events are identical.

Annotations

Read-only

It reads and never changes anything.

Arguments

This tool takes no arguments.

What it returns

{  "data": [    {      "id": "1284",      "name": "Zapier production",      "abilities": ["project:view-any", "project-user:view-any"],      "abilities_count": 2,      "scopes": {        "team_id": "a83f0d51-4c92-4b7e-8615-2fd9e70a3c86",        "project_ids": ["7f3d1c92-8b45-4e6a-9d21-5c8e0a4b6f13"]      },      "last_used_at": "2026-05-18T09:15:00Z",      "expires_at": null,      "created_at": "2026-05-01T10:05:00Z"    }  ],  "meta": { "total": 1 }}

How it fails

AUTHENTICATION_REQUIRED

no authenticated user on the request.

How is this guide?

Last updated on