API tokens
Give a platform — n8n, an app builder, a script — a token to call governed capabilities without a human sign-in. A token authenticates to its groups (the same access rules a person gets) and, optionally, to an allowlist of capabilities.
Auto skills run straight away. A write skill (confirm / verify) runs for a token only when you put it on that token's allowlist — that listing is the human decision, made once. A delegated confirm skill the token may run itself (it gets a preview first); a verify skill still stages for a person to release on Approvals. Any write not on the allowlist is refused, so a token is never a way around the gate.
Mint a token
Issued tokens
No tokens issued yet.