Skip to main content

Creating Access Tokens and Application Keys

Learn how to create, manage, and revoke Access Tokens and Application Keys, the credentials that connect CompanyCam to other tools and AI assistants.

Access Tokens and Application Keys are the credentials that let other tools, including AI assistants and custom integrations, connect to your CompanyCam data. This article covers the two credential types, their permission levels, and how to create, view, and revoke them.

This feature is available on select plans and is only available on the web app.


Personal Access Tokens vs. Application Keys

There are two kinds of credentials:

  • Personal Access Token: tied to you as an individual User. It acts like you and can only do what your account can. Use this for connecting an AI tool through the MCP, or any other quick, personal connection where the integration should act as you.

  • Application Key: tied to a registered Application, not a person. Use this for partner integrations and business-level custom integrations that should be identified as an app rather than as an individual.

Choose a Personal Access Token when one person just wants to connect a tool to their own account. Choose an Application Key when the connection should be identified as an app instead of a person.

Note: If you're connecting an AI tool through the MCP, use a Personal Access Token. New personal access tokens default to Read-only, so switch yours to read & write, or the AI tool won't be able to make any changes.


Permission levels

Every token or key is created with one of these levels:

  • Read only — can look but not change anything

  • Read & Write — read, plus create and update

  • Full access — read, write, and delete

  • Custom — choose specific permissions per resource

A token or key can never do more than the account that created it, no matter which level you choose.


Creating a Personal Access Token

Note: Only Admins and Managers can create a token or key.

  1. Click Integrations in the left-hand nav, then click Access Tokens.

  2. Click New Personal Access Token.

  3. Name it, add an optional description, choose a permission level, and set an expiration.

  4. Click Create token, then copy the token.


Creating an Application Key

Application Keys are tied to a registered Application. If you haven't registered one yet, do that first. See [Registering an Application].

  1. Click Integrations in the left-hand nav, then click Access Tokens.

  2. Click New Application Key.

  3. Select the Application it belongs to.

  4. Name it, add an optional description, choose a permission level, and set an expiration.

  5. Click Create token, then copy the key.


Setting an expiration

Tokens and keys can be set to expire in 7, 30, 60, or 90 days, or to never expire. New ones default to 30 days.


Revoking a token or key

Important: An Application Key acts as the User who created it. If that person is deactivated, the key stops working. Before deactivating someone tied to an active integration, reassign or recreate the key first.

Revoke a token or key any time from the Access Tokens page. Treat it like a password: if it's ever exposed, revoke it and create a new one.

Note: You might still see an older Access Tokens page under your User Icon that lists personal and application tokens together. That page is being phased out as customers move to the new one.


FAQs

What's the difference between the two credential types?

A Personal Access Token acts as you and is tied to your User account. An Application Key acts as a registered Application instead of a person.

Do Application Keys require a registered Application?

Yes. See Registering an Application for step-by-step instructions.

What happens when a token or key expires?

It stops working once it expires. Create a new one, or set the expiration to No expiry if the integration needs to keep running indefinitely.

Can a token do more than my account can?

No. A credential can never exceed the permissions of the account that created it, regardless of the permission level selected.

Why can't my AI tool make changes after connecting?

Personal Access Tokens default to read-only. Switch the token to Read & Write if you need the AI tool to create or update data.

Who can create or revoke a token?

Admins and Managers can create and revoke tokens and keys. Standard Users can't create tokens.

What happens to tokens from the old Access Tokens page?

Existing tokens from the previous Access Tokens page continue to work. New tokens and keys should be created from the new Access Tokens page going forward.

What resources are available if I'm building a custom integration?

If you're building a custom integration from scratch, see Building Custom Integrations with the API for more information.


💡 Need more help?

Contact our Support team — we're here Monday through Friday.

The CompanyCam Community has real job-site examples, templates, and tips from crews using this every day. Jump in with a question or just browse.

Did this answer your question?