Account & security
Personal access tokens for CI
Create scoped, expiring tokens for CI and scripts, and what happens when one leaks.
Tokens are for machines that can't open a browser — a CI job, a script. Create them in Settings → Local access (you'll confirm it's you first). A token is shown once; KODEO keeps only a keyed hash.
Choose what it can do
- Workspaces: all of yours, or only some. A project anywhere else looks like it doesn't exist.
- Write or read-only, and Git — or Git only for CI that just clones.
- Expiry: 7, 30, 60 or 90 days (Free: up to 30). A Team can set a shorter maximum. Seven days before it stops you get a notification with Regenerate.
Use it
KODEO_TOKEN=kdo_p_… npx @kodeohq/cli clone acme/storefront --jsonWith KODEO_TOKEN set, the CLI never prompts. Commands print versioned JSON with --json and use documented exit codes (kodeo help exit-codes).
If a token leaks
Tokens start with kdo_ and carry a checksum, so scanners recognise them. A token reported as exposed is revoked at once and you're told. You can also revoke any token yourself — anything using it stops immediately. Tokens end with everything that ends a sign-in: a password change, an email change or "This wasn't me".
Still have a question about this?
Assist answers from this article — in any language.
Was this helpful?