# API tokens

Create, manage, and rotate tokens for the API and MCP server.

## API tokens

An API token authenticates the REST API and the MCP server. It acts as you, inside one workspace. Treat it like a password.

<h2 id="format">Format</h2>
<p>
  A token is <code>fb_</code> followed by 32 alphanumeric characters — 35 in total. Send it as a bearer token:
</p>

```
Authorization: Bearer fb_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
```

<p>
  The same header works for <a href="/developers/rest-api">the API</a> and the <a href="/developers/mcp-server">MCP server</a>. Only a
  SHA-256 hash is stored, so a lost token cannot be recovered — create a new one.
</p>

<h2 id="limits">Limits</h2>
<ul>
  <li>
    <strong>10 tokens</strong> per person per workspace. Access tokens issued when you connect an OAuth app (<code>fbo_...</code>) sit on
    the same page but do not count.
  </li>
  <li>
    <strong>Expires 30 days after creation.</strong> There is no extend button — create a new token and delete the old one.
  </li>
  <li>
    <strong>One workspace.</strong> A token is bound to the workspace it was created in. A call that names another workspace, or a form in
    one, fails with <code>FORBIDDEN</code>, even when you are a member of both.
  </li>
  <li>
    <strong>No scopes.</strong> A token does everything you can do in that workspace. There is no read-only token.
  </li>
</ul>

> ℹ️ **Every plan has API access**
> <p>
>     Creating and using tokens is not gated by plan. Individual calls still are — scheduling request reminders needs Pro or Business, for
>     example, and answers with <code>UPGRADE_REQUIRED</code> otherwise.
>   </p>

<h2 id="create">Create a token</h2>

<p>
  The list then shows the name, the first 11 characters, when it was created, and when it expires. An expired token is marked{' '}
  <strong>Expired</strong> and stops authenticating.
</p>

<h2 id="rotate">Rotate a token</h2>

<h2 id="revoke">Revoke a token</h2>
<p>
  Deleting a token removes it permanently and it stops working on the next call — there is no grace period, and anything still using it
  starts getting <code>401 UNAUTHORIZED</code>. You can also rename a token with the pencil icon (up to 64 characters); renaming does not
  change its value.
</p>
<p>
  Only you see your own tokens — workspace admins cannot list or delete them. Leaving the workspace, or being removed from it, deletes them
  for you.
</p>

> ⚠️ **A token is full access**
> <p>Anyone holding it can act as you inside that workspace. If one leaks, delete it first and investigate second.</p>

<h2 id="oauth">OAuth instead</h2>
<p>
  A third-party app connecting on behalf of a user should use the OAuth flow instead of asking for a token. It gets an <code>fbo_...</code>{' '}
  access token, valid one hour and refreshable for 30 days, bound to the one workspace the user picked at consent. The user sees and
  disconnects those apps in <strong>Connected apps</strong> on the same page. See <a href="/developers/mcp-server#oauth">MCP server</a>.
</p>

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [MCP server](/developers/mcp-server) — Use formbase from AI agents
  - [Webhooks reference](/developers/webhooks-reference) — Payload schema and signing
</div>
