# What is a personal access token, & how does it secure API access? > A personal access token is a long-lived credential scoped to one account or workspace, generated specifically for scripts & automation instead of an actual login password. It can be revoked on its own without breaking anyone's personal login. Updated: 2026-09-24. ## Why automation needs its own credential A login password is built for a person typing it into a browser occasionally, with a session that expires & prompts for re-entry. A script or a CI job running unattended can't click through a login prompt, & using a personal password for that purpose means the automation shares the exact same access as the person's own account, with no way to tell which one did what. A personal access token solves this: a separate, long-lived credential generated specifically for a script or service, scoped to a specific account or workspace, that can be used in an `Authorization` header the same way a session token would be. ## How a token actually gets used A typical request includes the token in an authorization header alongside whatever else identifies the target workspace, & the receiving API checks it the same way it would check a normal login session, just without requiring an interactive login step. This is what makes unattended automation possible: no person has to be present clicking through a login flow each time the script runs. ## Why tokens are safer than sharing a login - A token can be revoked on its own, immediately cutting off that specific script or integration, without touching the person's own login - A token can carry an expiry or a specific scope, limiting exactly what it can do, unlike a full login which grants everything the account can do - Rotating a token, replacing it with a fresh one, doesn't require changing the underlying account password Any of these becomes a real problem the moment a shared password is used for automation instead: revoking access means changing the password for everyone, & there's no way to scope what the automation can specifically do versus everything the account can do. ## Handling a token securely - Never commit a token to a code repository, even a private one - Store it in an environment variable or a secrets manager, not hardcoded in a script - Treat a leaked token as equivalent to a leaked password: rotate it immediately - Give each integration its own token rather than reusing one token across several unrelated scripts, so revoking one doesn't break the others DunSocial's own tokens are worth the same handling discipline: treated as a real credential, not a throwaway string copied into whichever script needs it fastest. ## DunSocial's personal access tokens specifically DunSocial issues personal access tokens for exactly this purpose: authenticating the CLI, a custom script, or a CI job against a specific workspace without an interactive login each time. A token is generated & managed from account settings, & it can be revoked independently the moment it's no longer needed or if it's ever exposed, without affecting anyone's normal login to the web app. ## A practical habit worth building Treating a personal access token with the same care as a database password, never logged, never pasted into a chat, never committed, is a habit worth building early, since a leaked token grants real write access to whatever accounts that workspace has connected. That's true whether the token belongs to DunSocial or any other service exposing a similar credential. ## Related guides - [How to schedule social media posts from the command line](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-schedule-social-media-posts-from-the-command-line.md) - [How to connect an AI agent to your social media accounts safely](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-connect-an-ai-agent-to-your-social-media-accounts-safely.md) - [How to automate social media posting in a CI/CD pipeline](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-automate-social-media-posting-in-a-ci-cd-pipeline.md) - [What are webhooks for social media posting?](https://www.dunsocial.com/hub/social-media-automation-for-developers/what-are-webhooks-for-social-media-posting.md) ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/social-media-automation-for-developers/what-is-a-personal-access-token-and-how-does-it-secure-api-access. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login