Skip to content

Credentials

Choose the credential made for the door you are using, and revoke it when its owner or purpose changes.

Tindre credentials are typed and not interchangeable. A credential used on the wrong door returns an authentication failure rather than being treated as a weaker permission.

PrefixCredentialWhere it works
tnd_pat_Personal access tokenREST API and MCP, as its owner
tnd_oat_OAuth access tokenMCP only
tnd_ort_OAuth refresh tokenToken exchange only
tnd_org_Organization keyRead-only open Standards lane

Personal access tokens

A personal token has no independent scopes. It uses the owner’s live access roles and Role visibility, is bound to one organization, and is shown only once. Create, list, and revoke your own tokens under Settings → API & MCP.

OAuth tokens

An AI client receives an MCP-only access token and stores the rotating refresh token. Revoke the connected-client consent rather than trying to manage the individual token values.

Organization keys

An organization key belongs to the organization and no person. It can read only active Standards marked Open, never drafts, history, Role-restricted content, writes, or proposals.

No credential mints another

Creating personal tokens and organization keys requires interactive sign-in. Revoke leaked credentials immediately; plaintext cannot be recovered.