Keep your devBoard tokens safe
A token is a secret key that lets a tool act as you. You make one in the devBoard Mac app, under Settings → Developer. This page says what a token can reach, what it cannot, and what to do if one leaks.
MCP is the open standard AI assistants use to reach other tools. devBoard checks your token on every MCP call and on every REST API call. An API is a way for a script to talk to an app without a screen.
What a token can reach
A token works as you, with your role. Through the MCP tools it can:
- Read projects, columns, tags (labels), releases, people and saved views.
- Find, read, create, edit, move and archive tasks.
- Add comments, and edit or delete your own.
- Run your timer, log time, and read your timesheet and inbox.
- Manage your private to-do list. That list follows you across workspaces, so any of your tokens can reach it.
The same token works on the small REST API, for scripts and CI. See using the REST API from CI.
What it cannot do
Some things stay in the app on purpose. A token cannot:
- Delete tasks. It can archive them, and you can bring them back.
- Add, remove or change members and invites.
- Create, rename or delete projects or columns.
- Add, open or delete attachments.
- Change workspace settings or make more tokens.
One workspace per token
A token belongs to the workspace that was open when you made it. It cannot see any other workspace, and nothing in a call can change that.
Ana is a freelancer with three clients: a bakery app, a hotel site and a clinic booking app. Each is its own workspace, so she has three tokens. The bakery token can never show her the clinic's tasks.
Roles
devBoard checks your role on every call.
| Role | Can make a token | What the token can do |
|---|---|---|
| Owner or admin | Yes | All a member can, plus plan and ship releases and add tags |
| Member | Yes | Read and change tasks, comments and your own time |
| Guest | No | Only read, if it was made before the role changed |
If an admin lowers your role, so does your token. If you leave the workspace, it stops working.
Revoking a token
Open Settings → Developer in the Mac app. Find the token by its name and its first few characters. Click Revoke. It stops working at once, and the next call with it gets a 401 error.
You can only see and revoke your own tokens. An admin cuts off someone else by removing them from the workspace.
Give each tool its own token, named after it, like "Cursor" or "CI". Then you can revoke one without breaking the rest.
Only a hash is stored
devBoard keeps a hash of each token, not the token. A hash is a one-way fingerprint. It can check a token but cannot be turned back into one. So nobody can read your token out of devBoard, not even us.
Where to keep it
Treat a token like a password. Never commit it to git.
| Tool | Where the token sits | Safe to commit |
|---|---|---|
| Claude Code | Your user config, outside the project | Do not use --scope project with a token |
| Cursor | ~/.cursor/mcp.json or .cursor/mcp.json |
No. Add .cursor/mcp.json to .gitignore |
| VS Code | Its own storage. The file only holds a prompt | Yes |
| Claude Desktop | claude_desktop_config.json in the app's folder |
Not in a project |
| CI | Your CI's secret store, like GitHub Actions secrets | Never in the workflow file |
Every token starts with devboard_, so a stray one is easy to search for. The VS Code setup keeps the token out of the project.
If a token leaks
- Revoke it in Settings → Developer. Do this first.
- Make a new token with a new name, and put it where the old one was.
- Look at the activity log on your recent cards. What the token did shows under your name.
- If it was in git, take it out. The revoke already made it useless.
More on the MCP page. Setup steps for each tool are in the guides.
Questions people ask
Do devBoard tokens expire?
No. A token works until you revoke it or leave the workspace. Revoke the ones you no longer use.
Can I make a token on my phone?
No. The Developer section only shows in the Mac app. Make the token there, then use it from any computer. See where devBoard runs.
Free while in early access; paid plans will be one plain number, posted here first.
Download on the App Store Get it on Google Play Connect your AI assistant