Paper documentation
Personal API

Access tokens

The two kinds of token, the permissions of each, and how to keep and revoke them.

A token is a key you hand to a program. It has this format:

paper_k3m9x2ab_Q7wLc2…(40 characters)
  • paper_ marks it as a Paper token. Tools that look for leaked secrets recognize this prefix.
  • The 8 characters in the middle identify the token. They show up in the token list, so you know which is which.
  • The last 40 are the secret. The server keeps only a digest (hash) of it, so not even Paper can show the token again. If you lose it, revoke it and create another.

The two kinds

Secure (for AI)Regular
What forGiving a vault to an AI to work onYour own automations
What it reachesAn isolated copy of one vaultThe real vaults, through Google Drive
ChangesWait for your reviewTake effect right away
Calendar and filesNoIf you allow
Needs Google allowed for the APINoYes

When in doubt, use secure. If the AI makes a mistake, the real vault stays intact.

Permissions

When creating a regular token, you choose:

PermissionOptions
Each vaultNo access, Read, Read and edit
Protected pagesHide (the token doesn't even know they exist) or Show only the title
"Paper" calendarNo access, Read events, Read and create events
Send filesYes or no
Expiry7 days, 30 days, 90 days or no expiry

Even with "Show only the title", the content of protected pages never leaves: the request answers 423.

The secure token has fixed permissions: it reads and edits only its own copy.

See how the token looks to the API

curl https://wire.ia.br/api/v1/me -H "Authorization: Bearer $PAPER_TOKEN"
{
  "conta": { "id": "3f2a…(32 characters)", "nome": "Ana" },
  "token": {
    "id": "k3m9x2ab",
    "nome": "Task script",
    "tipo": "normal",
    "permissoes": {
      "vaults": { "principal": "editar", "cmg2k1x9a4tz": "ler" },
      "protegidas": "ocultar",
      "agenda": "ler",
      "anexos": false
    },
    "venceEm": "2026-11-01T12:00:00.000Z"
  },
  "limites": { "perMinute": 60, "perDay": 5000, "uploadsPerDay": 30, "uploadBytes": 10485760, "pageBytes": 1048576 },
  "documentacao": "https://wire.ia.br/documentation/agents/raw.json"
}

Field names and values are in Portuguese: tipo is seguro (secure) or normal (regular); vault access is ler (read) or editar (edit); protegidas is ocultar (hide) or titulo (title only); agenda is nenhum, ler or editar.

Keep it safe

  • Keep it in an environment variable or a password manager. Never in public code, screenshots or group messages.
  • One token per program. That way, revoking one doesn't take down the others.
  • Give only the permissions the program needs.

Revoke

In Settings → Developer → Active tokens, tap Revoke. The token stops working on the next request. The list also shows when each token was last used and how many times.

A leaked token used for abuse leads to the ban of the account that owns it. If you suspect a leak, revoke it before anything else.

On this page