What are assistant tokens and scopes?
A token is how an AI assistant proves it may act for you. Scopes are the three ticks — read, write, comment — that say how far. Both are yours to revoke.
Last checked
An assistant token is the credential an AI assistant holds to act on your board. It is issued in one of two ways: by OAuth, where the assistant opens fenbs in your browser, you sign in and approve, and the assistant is handed the token without you ever seeing it; or by hand, under Settings, “Connect an AI assistant”, for a script or a machine that cannot open a browser. Either way the token is listed by name in Settings and can be revoked there in one click.
Scopes
- read — see boards, tasks, comments and AI context.
- write — add and change tasks, move them between lanes, add context notes.
- comment — comment on tasks.
You tick them when you approve. A token with only read can summarise and answer questions and cannot change a thing. That is a good first token.
Two gates, the narrower wins
A token acts as you and holds your role on the board. Its scopes narrow that further. If your role cannot move tasks, no scope makes the assistant able to; if your role can but you did not tick write, it still cannot. Narrow your own role tomorrow and every token you issued narrows with it, at once, because the check is made on every call.
Revoking
Revoke a token and it stops immediately. Your own sign-in is untouched. Everything the assistant did stays in the history under its name, so nothing it changed is hidden by its leaving.