Skip to content

Authentication

Send your personal access token to /api/graphql in the HTTP header:

Authorization: Bearer YOUR_PERSONAL_ACCESS_TOKEN

Use HTTPS. Personal access tokens authenticate GraphQL requests; they do not authenticate to the sign-in service, PowerSync, assistant chat, or internal worker and protocol-agent endpoints.

A token inherits its owner’s current organization memberships and permissions. Permission changes take effect on subsequent requests. Queries for an organization require the corresponding membership and permissions.

Tokens currently have no independent scopes or organization restriction. A token can act across the organizations its owner can access, so choose its owner accordingly and store it as securely as an account credential.

Tokens expire after 90 days by default. When creating one, you can choose a future expiry up to 365 days away. Expired or revoked tokens cannot authenticate.

Manage tokens in Account → API tokens while signed in to the dashboard. Token creation, listing, and revocation require a signed-in session; a personal access token cannot manage other tokens. Signing out does not revoke a token.

To rotate a token:

  1. Create a replacement in your account.
  2. Update the integration’s secret and verify a request succeeds.
  3. Revoke the old token from your account.
  • No authenticated identity: check the header, expiry, revocation, and that you are calling the environment where the token was created.
  • Permission errors: check the owner’s organization membership and roles.
  • Unexpected identity in a browser client: an existing signed-in session takes precedence over a personal access token. Use a server-side client without browser session cookies for token-based integrations.

Do not log token values. GraphQL errors can appear in an HTTP 200 response; inspect both the status and the response body.