Keep your devBoard tokens safe

A token is a secret key that lets a tool act as you. You make one in the devBoard Mac app, under Settings → Developer. This page says what a token can reach, what it cannot, and what to do if one leaks.

MCP is the open standard AI assistants use to reach other tools. devBoard checks your token on every MCP call and on every REST API call. An API is a way for a script to talk to an app without a screen.

What a token can reach

A token works as you, with your role. Through the MCP tools it can:

The same token works on the small REST API, for scripts and CI. See using the REST API from CI.

What it cannot do

Some things stay in the app on purpose. A token cannot:

One workspace per token

A token belongs to the workspace that was open when you made it. It cannot see any other workspace, and nothing in a call can change that.

Ana is a freelancer with three clients: a bakery app, a hotel site and a clinic booking app. Each is its own workspace, so she has three tokens. The bakery token can never show her the clinic's tasks.

Roles

devBoard checks your role on every call.

Role Can make a token What the token can do
Owner or admin Yes All a member can, plus plan and ship releases and add tags
Member Yes Read and change tasks, comments and your own time
Guest No Only read, if it was made before the role changed

If an admin lowers your role, so does your token. If you leave the workspace, it stops working.

Revoking a token

Open Settings → Developer in the Mac app. Find the token by its name and its first few characters. Click Revoke. It stops working at once, and the next call with it gets a 401 error.

You can only see and revoke your own tokens. An admin cuts off someone else by removing them from the workspace.

Give each tool its own token, named after it, like "Cursor" or "CI". Then you can revoke one without breaking the rest.

Only a hash is stored

devBoard keeps a hash of each token, not the token. A hash is a one-way fingerprint. It can check a token but cannot be turned back into one. So nobody can read your token out of devBoard, not even us.

Where to keep it

Treat a token like a password. Never commit it to git.

Tool Where the token sits Safe to commit
Claude Code Your user config, outside the project Do not use --scope project with a token
Cursor ~/.cursor/mcp.json or .cursor/mcp.json No. Add .cursor/mcp.json to .gitignore
VS Code Its own storage. The file only holds a prompt Yes
Claude Desktop claude_desktop_config.json in the app's folder Not in a project
CI Your CI's secret store, like GitHub Actions secrets Never in the workflow file

Every token starts with devboard_, so a stray one is easy to search for. The VS Code setup keeps the token out of the project.

If a token leaks

More on the MCP page. Setup steps for each tool are in the guides.

Questions people ask

Do devBoard tokens expire?

No. A token works until you revoke it or leave the workspace. Revoke the ones you no longer use.

Can I make a token on my phone?

No. The Developer section only shows in the Mac app. Make the token there, then use it from any computer. See where devBoard runs.

Free while in early access; paid plans will be one plain number, posted here first.

Download on the App Store Get it on Google Play Connect your AI assistant