How to Create a Personal Access Token
A Personal Access Token (PAT) lets a Claude installation authenticate to Gavana without receiving your browser session. It is scoped, named, expiring, and revocable. Behind the scenes it uses Gavana’s existing Agent Access security layer; you only ever create and use one PAT for a Claude installation.
Steps
Step 1: Sign in to Gavana
Step 2: Open Personal Access Tokens
Open the account menu and choose Personal Access Tokens.
Step 3: Name the Claude installation or device
Give the token a descriptive name (for example, Claude Code · MacBook Air or
Claude Desktop · Studio iMac). Create one PAT per installation or device —
never share it between people or machines. The name appears in node and activity
provenance so you can tell which Claude installation made a change.
Step 4: Choose scopes
Select only the permissions the client needs:
| Scope | Grants |
|---|---|
canvas:read | Read canvas graphs |
canvas:write | Change canvases (requires canvas:read) |
asset:read | Read asset references |
image:generate | Generate/edit images, upload local raster inputs, and start any Recipe, including text-only Recipes (requires canvas:read, canvas:write, asset:read) |
job:manage | Observe, resume, wait for, and cancel shared Runs; required for default CLI/MCP waiting |
The token form selects dependent scopes automatically — for example, choosing image:generate also enables the three scopes it depends on.
For normal Claude MCP execution, also select job:manage; without it Claude
can start work but cannot poll, wait for, or cancel the returned Run.
Step 5: Set an expiry
Tokens expire after 1–90 days. Choose the shortest expiry that’s practical.
Step 6: Copy the PAT and connect Claude
Copy the PAT immediately — Gavana never shows it again after this screen. Use the provided Claude Code command or Claude Desktop settings. Both use this same PAT; do not create or paste a separate agent token.
Tips
- Never paste a PAT into a chat, email, ticket, shared document, or repository.
- Use a separate, descriptively named PAT per Claude installation or device.
- You can revoke a PAT at any time from Personal Access Tokens.