Skip to Content
Personal Access TokensCreate a Personal Access Token

How to Create a Personal Access Token

A Personal Access Token (PAT) lets a Claude installation authenticate to Gavana without receiving your browser session. It is scoped, named, expiring, and revocable. Behind the scenes it uses Gavana’s existing Agent Access security layer; you only ever create and use one PAT for a Claude installation.

Steps

Step 1: Sign in to Gavana

Step 2: Open Personal Access Tokens

Open the account menu and choose Personal Access Tokens.

Step 3: Name the Claude installation or device

Give the token a descriptive name (for example, Claude Code · MacBook Air or Claude Desktop · Studio iMac). Create one PAT per installation or device — never share it between people or machines. The name appears in node and activity provenance so you can tell which Claude installation made a change.

Step 4: Choose scopes

Select only the permissions the client needs:

ScopeGrants
canvas:readRead canvas graphs
canvas:writeChange canvases (requires canvas:read)
asset:readRead asset references
image:generateGenerate/edit images, upload local raster inputs, and start any Recipe, including text-only Recipes (requires canvas:read, canvas:write, asset:read)
job:manageObserve, resume, wait for, and cancel shared Runs; required for default CLI/MCP waiting

The token form selects dependent scopes automatically — for example, choosing image:generate also enables the three scopes it depends on. For normal Claude MCP execution, also select job:manage; without it Claude can start work but cannot poll, wait for, or cancel the returned Run.

Step 5: Set an expiry

Tokens expire after 1–90 days. Choose the shortest expiry that’s practical.

Step 6: Copy the PAT and connect Claude

Copy the PAT immediately — Gavana never shows it again after this screen. Use the provided Claude Code command or Claude Desktop settings. Both use this same PAT; do not create or paste a separate agent token.

Tips

  • Never paste a PAT into a chat, email, ticket, shared document, or repository.
  • Use a separate, descriptively named PAT per Claude installation or device.
  • You can revoke a PAT at any time from Personal Access Tokens.