formbasedocs
Go to appApp

Developers

API tokens

An API token authenticates the REST API and the MCP server. It acts as you, inside one workspace. Treat it like a password.


Format

A token is fb_ followed by 32 alphanumeric characters — 35 in total. Send it as a bearer token:

text
Authorization: Bearer fb_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

The same header works for the API and the MCP server. Only a SHA-256 hash is stored, so a lost token cannot be recovered — create a new one.

Limits

  • 10 tokens per person per workspace. Access tokens issued when you connect an OAuth app (fbo_…) sit on the same page but do not count.

  • Expires 30 days after creation. There is no extend button — create a new token and delete the old one.

  • One workspace. A token is bound to the workspace it was created in. A call that names another workspace, or a form in one, fails with FORBIDDEN, even when you are a member of both.

  • No scopes. A token does everything you can do in that workspace. There is no read-only token.

Every plan has API access

Creating and using tokens is not gated by plan. Individual calls still are — scheduling request reminders needs Pro or Business, for example, and answers with UPGRADE_REQUIRED otherwise.

Create a token

  1. 1

    Open OAuth and API Keys

    In the sidebar, under your workspace. Tokens live in the API Keys card.

  2. 2

    Click Create token

    Name it in the Create API token dialog — "CI/CD Pipeline", "n8n production".

  3. 3

    Copy it now

    The API token created dialog shows the value once. Copy & Close, and the value is gone for good.

  4. 4

    Store it in your secrets manager

    Never commit it, and never ship it to a browser.

The list then shows the name, the first 11 characters, when it was created, and when it expires. An expired token is marked Expired and stops authenticating.

Rotate a token

  1. 1

    Create the replacement

    Give it a name that says which generation it is, like "n8n production v2".

  2. 2

    Roll it out

    Update every consumer. Both tokens work while you switch.

  3. 3

    Delete the old one

    Use the trash icon on its row and confirm in Delete API token?.

Revoke a token

Deleting a token removes it permanently and it stops working on the next call — there is no grace period, and anything still using it starts getting 401 UNAUTHORIZED. You can also rename a token with the pencil icon (up to 64 characters); renaming does not change its value.

Only you see your own tokens — workspace admins cannot list or delete them. Leaving the workspace, or being removed from it, deletes them for you.

OAuth instead

A third-party app connecting on behalf of a user should use the OAuth flow instead of asking for a token. It gets an fbo_… access token, valid one hour and refreshable for 30 days, bound to the one workspace the user picked at consent. The user sees and disconnects those apps in Connected apps on the same page. See MCP server.

Next steps