Personal Access Tokens
A personal access key is a credential that acts as you: it carries your identity and role, and what it can do is what you can do in the application. You use one where a tool works as a person rather than as the organization, and it's the only credential calendar entries and agent connections accept.
Create your access key
Open your profile (My Profile in the avatar menu) and go to the API Access tab. Any member can create their own key; no admin role is required. You hold one live key per organization: if you belong to several organizations, each has its own key, managed while you are signed in to that organization.
Click Create access key. The Access Key Created dialog shows the full key once. Copy it with the copy button and store it securely; you will not be able to see it again. Click Done when you have it. The tab then shows the start of your key, an Active badge, and the date it was created.
If your organization has not enabled agent access yet, the tab says so. You can still create your key now; it starts working as soon as an administrator enables agent access.
You send it exactly like an API key, as a bearer token:
curl https://your-abletime-host/api/public/v2/tasks \
-H "Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN"What it reaches
A personal access key works on tasks, projects, users, and calendar entries; calendar entries accept nothing else, and only ever show you your own. The rest of the API takes an organization key instead. The full split is on Authentication.
Unlike an organization key, a personal key carries no grants. What a request may do is decided by your role and your project membership, exactly as it would be in the app. Because of this, all actions taken using the key are recorded as if the user performed it themselves.
Agents and MCP
Agent connections authenticate as a person, so they run on your personal access key, and they require agent access to be enabled for the organization: an admin or owner switches on Agent access (MCP) under Settings → Integrations → API Keys.
In an app you configure yourself, you supply the endpoint and your key. On a hosted browser platform, you add the endpoint and click Approve on AbleTime's consent page; the platform then holds a connection of its own that acts as you.
Rotation is revocation
There is no separate revoke: to invalidate a key, click Rotate on the same API Access tab and confirm in the Rotate Access Key dialog. The old key stops working immediately, and the new key is shown once in the Access Key Created dialog. An app configured with the key itself is cut off at once and needs the new key pasted in. A browser connection keeps working across rotation, because it follows whichever of your keys is currently live; to sever one, remove the connector on the platform's side.
The credential model in full is on Authentication.