Access tokens
Every Access tokens tool, with the scope it needs, its arguments and the API operation it calls.
4 tools
Create personal access tokens
Changes dataatlas_pats_create
Mint a new Personal Access Token. The plaintext token is returned ONCE in the response.
- Scope
pats:manage- Calls
- Example prompt
- Mint a read-only token for the dashboard service.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Human-readable label for this token. |
scopes | array of string | No | Scope strings (e.g. "tasks:read", "projects:write"). See /v1/docs. Empty means no permissions. |
expiresAt | string (date-time) | No | ISO-8601 expiry. Omit for never-expires. |
allowedIps | array of string | No | Optional IP allowlist (CIDR or single IPs). |
List personal access tokens
Read onlyatlas_pats_list
List the calling user's Personal Access Tokens (token hashes are not returned).
- Scope
pats:manage- Calls
- Example prompt
- Show me all my Atlas API tokens.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
limit | integer | No |
Revoke personal access tokens
Destructiveatlas_pats_revoke
Revoke a PAT immediately. Subsequent requests with that token return 401.
- Scope
pats:manage- Calls
- Example prompt
- Revoke the token I created last week.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | PAT id (e.g. pat_...). |
Rotate personal access tokens
Destructiveatlas_pats_rotate
Rotate a Personal Access Token. The old token is revoked, a replacement PAT is created, and the new plaintext token is returned ONCE.
- Scope
pats:manage- Calls
- Example prompt
- Rotate the dashboard service token and keep its read-only scopes.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | PAT id (e.g. pat_...). |
name | string | No | Replacement human-readable label. |
scopes | array of string | No | Replacement scope list. Omit to preserve the existing scopes. |
expiresAt | string (date-time) | null | No | Replacement ISO-8601 expiry. Pass null to clear expiry; omit to preserve it. |
allowedIps | array of string | No | Replacement IP allowlist. Omit to preserve the existing allowlist. |