Personal Access Tokens

Personal access tokens let you authenticate with the A vs B CLI and REST API without using your email and password. Each token belongs to your account personally. It acts with your permissions in every organization you belong to, and works across all of them. It is one of four A vs B credentials: see Credentials for the full map.

Building CI or another automation? Use a service token instead

A personal access token is yours. If it stops working when you leave the team, so does anything using it. For CI/CD pipelines and other automation owned by your organization, create a service token instead, from Organization Settings → Service Tokens.

Personal access tokens: create, inspect (values stay masked), and revoke from Account Settings → Personal Access Tokens.

What are personal access tokens?

A personal access token (PAT) is a long, randomly generated string that acts as a credential. You pass it in API requests or CLI commands instead of your password. Tokens are useful when:

  • You want to run the A vs B CLI in a script or a CI/CD pipeline.
  • You are building a tool or integration that calls the A vs B REST API on your behalf.
  • You want to grant a specific tool access to your account without sharing your real password.

Revoke a token at any time. Doing so does not affect your account password or any other token.

Token format

All personal access tokens start with the prefix avsb_pat_ followed by a long random string, for example: avsb_pat_abc123xyz.... The prefix makes an A vs B token easy to spot in a log or a config file, and easy to tell apart from an organization service token, which starts with avsb_svc_.

A personal access token also works as a Bearer credential on the management API (/api/v1), where it carries your own permissions rather than a fixed scope list. See Public API: Authentication.

Creating a token

1

Open Account Settings

Click your avatar or initials in the top-right corner of the page, then click Account in the menu that opens.

2

Go to the Personal Access Tokens tab

Click the Personal Access Tokens tab at the top of the Account Settings page. If you do not see this tab, your role does not include token access; ask an owner or admin in your organization.

3

Click Create token

Click the Create token button. A dialog opens with a Token name field.

4

Enter a name

Give the token a descriptive name that explains what it will be used for, for example "CI/CD pipeline", "Local development CLI", or "Data export script". The name is only for your reference and does not affect the token's behavior.

5

Click Create token again, inside the dialog

This submits the form and generates the token.

6

Copy the token immediately

Your new token is displayed once, in full. Copy it and store it in a secure location, for example in your password manager, a secrets manager, or your CI/CD platform's environment variables. The token will not be shown again after you close or dismiss the dialog.

  1. Copy this value now. A vs B does not show it again.
  2. Click Copy to copy the full token to your clipboard.
Save your token immediately

Your token is shown only once at the moment it is created. It cannot be retrieved later: if you lose it, you will need to revoke it and create a new one. Never paste a token into a chat message, email, or code repository.

Token limit

Each user can have a maximum of 10 personal access tokens active at one time. If you reach the limit, revoke a token you no longer need before creating a new one.

Viewing your tokens

The Personal Access Tokens tab lists all your active tokens. For each token you can see:

  • Name: the label you gave the token when creating it
  • Created: the date the token was generated, for example "Aug 12, 2026"
  • Last used: the most recent date this token authenticated a request, in the same date format. If the token has never been used, this shows "Never".

The token value itself is not shown in the list, only the name and metadata. This is intentional: if someone gains access to your account, they cannot see your existing tokens.

Revoking a token

To revoke a token, click the Revoke button next to it in the token list. There is no extra confirmation step, so make sure you have the right one before you click. Revocation is immediate: any script or tool using that token starts getting authentication errors right away. Create a new token and update your tool if you need to restore access.

Rotate tokens regularly

Even if a token has not been compromised, it is good security practice to revoke old tokens and create new ones periodically, especially for tokens that have been in use for many months. Check the Last used timestamp to identify tokens that are no longer actively used and can be safely revoked.

Was this helpful?