Account-level tokens (fgp_) for Terraform, the Flaggr CLI, the local MCP server and scripts — tiers, limits, rotation and what they can never do
Last updated October 9, 2026
Personal Access Tokens
A personal access token (fgp_…) belongs to you and covers your whole account. It acts as you in every project and organization you can access, limited to the tier you pick when you create it. Use it for automation that spans projects: the Terraform provider, the Flaggr CLI, the MCP server over stdio and your own scripts.
Your roles always apply as well. A token never does more than you can do yourself — if you lose access to a project, every token you own loses it too.
Which token should I use?
| Token | Prefix | Scope | Use it for |
|---|---|---|---|
| Project API token | fgr_ | One project | SDKs and flag evaluation, OFREP, single-project CI jobs |
| Personal access token | fgp_ | Every project and organization you can access | Terraform, the CLI, the local MCP server, scripts across projects |
| MCP connector (OAuth) | mcp_ | The projects you consented to | Claude, ChatGPT, Cursor and other assistants on the hosted /mcp endpoint |
Personal access tokens can't evaluate flags, on purpose: SDK endpoints accept cross-origin requests, and an account-wide credential must never end up in frontend or mobile code. SDKs use project API tokens.
Format
fgp_3f9a… # fgp_ followed by 64 lowercase hex characters (32 random bytes)
- Flaggr stores only the SHA-256 hash of the secret, plus its last 4 characters so you can tell tokens apart (
fgp_…a1b2). The secret is shown once, when the token is created or rotated. - Secret scanners can match the pattern
fgp_[0-9a-f]{64}.
Tiers
| Tier | What it can do (within your roles) |
|---|---|
read | List and export projects, services, flags, settings and analytics. GET requests, plus the POSTs that only read: POST /api/flags/{key}/explain, /simulate, /advice and /code-refs, and POST /api/projects/{id}/cohorts/{cohortId}/evaluate. |
write | Also create, change and delete flags, services, rollouts, alert channels and rules, and metric sources. |
admin | Also manage members, teams, environments and project settings, list and revoke project API tokens, create organizations and projects, and change organization settings. |
Owner actions
Deleting a project or an organization, and ownership changes (granting the owner role, demoting or removing an owner, transferring ownership), are owner actions. An admin token can do them only if you tick Allow owner actions when you create it — it's off by default and not available on other tiers. You still need the owner role yourself.
Terraform needs owner actions for terraform destroy, or to remove a flaggr_project or flaggr_organization resource. Without the opt-in those deletes fail with HTTP 403.
Limits
- Up to 20 active tokens per user (expired and revoked tokens don't count).
- Every token expires: choose 7, 30, 90 (default), 180 or 365 days. Rotate a token before it expires to keep the same name, tier and lifetime.
Creating a token
In the dashboard
- Open Profile → Personal access tokens (
/console/profile#personal-access-tokens). - Click New token, name it (e.g.
Terraform (production)), pick a tier and an expiry. - For Terraform deletes, choose Admin and tick Allow owner actions.
- Copy the token — it won't be shown again.
With flaggr login
Install the Flaggr CLI from github.com/flaggr-dev/flaggr-cli (see CLI).
flaggr login (and the MCP server's login tool) open /auth/cli. Choose All my projects to mint a write personal access token that expires in 90 days and is saved to ~/.flaggr/config.json. One project still mints a project API token. The page hands the token to the CLI (or the MCP server) in a form POST to its localhost callback — never in a URL, which your browser history would keep. A CLI or MCP server older than this release gets an "out of date" message and no token: update it, or create a token here and run flaggr login --token.
Management endpoints
Personal access tokens are managed only from a signed-in dashboard session. These endpoints refuse every token — connector, project API token, JWT or personal access token:
| Method | Path | |
|---|---|---|
GET | /api/users/me/personal-tokens | List your tokens (never the secret or its hash) |
POST | /api/users/me/personal-tokens | Create: { "name", "tier", "expiresInDays", "allowOwnerActions" } → { "token", "value" } |
DELETE | /api/users/me/personal-tokens/{id} | Revoke |
POST | /api/users/me/personal-tokens/{id}/rotate | Rotate: optional { "expiresInDays" } → { "token", "value", "rotatedFrom" } |
Creating or rotating a token also needs a verified email address: an unverified session gets 403 with "error": "Verify your email address first" and code: "EMAIL_NOT_VERIFIED". Listing and revoking work either way.
Using a token
Send it as a Bearer token to the control plane, https://flaggr.dev:
export FLAGGR_API_TOKEN="fgp_your_token_here"
# Who is this token, and what can it reach?
curl -s https://flaggr.dev/api/users/me -H "Authorization: Bearer $FLAGGR_API_TOKEN" | jq '.credential'- Terraform reads
FLAGGR_API_TOKEN(or the provider'sapi_token). - CLI:
flaggr login --token fgp_…saves it. - MCP server over stdio: set
FLAGGR_API_TOKENin the server'senv.
Not for evaluation
The SDK and evaluation endpoints (/api/flags/evaluate, /api/ofrep/*, Connect and gRPC-Web, /api/sdk-config, SSE streams, event ingestion) reject personal access tokens with 403. The data plane at api.flaggr.dev refuses them too. Until the data plane update, it treats a personal access token like any key it doesn't know: 401 {"error":"UNAUTHENTICATED"}, and unauthenticated for Connect and gRPC-Web calls (flaggr eval included). After the update:
- REST and SSE requests get
403{"error":"FORBIDDEN","message":"personal access tokens can't evaluate flags or call SDK endpoints — use a project API token (SDK key)"}. - Single-flag OFREP requests get
403{"key":"<flag>","errorCode":"PROVIDER_NOT_READY","errorDetails":"Forbidden: personal access tokens can't evaluate flags or call SDK endpoints — use a project API token (SDK key)"}. - Connect and gRPC-Web calls get
PERMISSION_DENIEDwith the same message.
The MCP tools evaluate_flag, watch_flag_updates and measure_round_trip, and flaggr eval, need a project API token:
FLAGGR_API_TOKEN=fgr_your_project_token flaggr eval bool -k new-checkout -s <service-id>What a personal access token can never do
So a leaked token can't outlive its own revocation or widen its access, personal access tokens never:
- create or rotate project API tokens, flag trigger URLs, share links (view or toggle) or invitations;
- approve OAuth consent or CLI/device logins, or manage MCP connections;
- accept invitations;
- change SSO configuration, open billing checkout or the billing portal, or set up demo data;
- create, rotate or revoke personal access tokens.
Use the dashboard for these.
Rotation and revocation
Revoking or rotating a token takes effect immediately; other servers stop accepting the old secret within about 10 seconds (within about 30 seconds on a deployment without a shared cache). Rotation issues a new secret with the same name, tier, owner-actions setting and lifetime (or a new expiresInDays) and revokes the old one at once — update the secret wherever it's stored. Expired tokens can't be rotated; create a new one.
flaggr logout and the MCP server's logout tool only forget the token on that machine; it keeps working until you revoke it here or it expires.
Errors
| Status | Meaning |
|---|---|
401 Unauthorized | The token is unknown, expired or revoked |
403 Forbidden: personal access token is read-only | A read token made a change (any request other than GET or one of the read-only POSTs) |
403 Forbidden: personal access token lacks the admin tier — … | The request needs the admin tier |
403 Forbidden: deleting a project or organization needs an admin personal access token created with owner actions allowed — … | Owner action without the opt-in |
403 Forbidden: personal access tokens can't evaluate flags or call SDK endpoints — … | Use a project API token |
403 FORBIDDEN (REST, SSE), PROVIDER_NOT_READY (single-flag OFREP) or PERMISSION_DENIED (Connect, gRPC-Web) from api.flaggr.dev, after the data plane update | A personal access token was sent to the data plane: use a project API token. Until the update, the data plane answers it like an unknown key: 401 UNAUTHENTICATED (Connect, gRPC-Web: unauthenticated) |
403 EMAIL_NOT_VERIFIED on create or rotate | In the console choose Send verification email (on the notice or the banner), open the link, then I've verified — retry. GitHub sign-ins always need this once. |
403 Forbidden: personal access tokens can't do this — … | A dashboard-only action (see above) |
403 Forbidden: You need '<permission>' permission | Your own role doesn't allow it |
409 on create | You already have 20 active tokens — revoke one |