Tindre credentials are typed and not interchangeable. A credential used on the wrong door returns an authentication failure rather than being treated as a weaker permission.
| Prefix | Credential | Where it works |
|---|---|---|
tnd_pat_ | Personal access token | REST API and MCP, as its owner |
tnd_oat_ | OAuth access token | MCP only |
tnd_ort_ | OAuth refresh token | Token exchange only |
tnd_org_ | Organization key | Read-only open Standards lane |
Personal access tokens
A personal token has no independent scopes. It uses the owner’s live access roles and Role visibility, is bound to one organization, and is shown only once. Create, list, and revoke your own tokens under Settings → API & MCP.
OAuth tokens
An AI client receives an MCP-only access token and stores the rotating refresh token. Revoke the connected-client consent rather than trying to manage the individual token values.
Organization keys
An organization key belongs to the organization and no person. It can read only active Standards marked Open, never drafts, history, Role-restricted content, writes, or proposals.
No credential mints another
Creating personal tokens and organization keys requires interactive sign-in. Revoke leaked credentials immediately; plaintext cannot be recovered.