Access tokens
The two kinds of token, the permissions of each, and how to keep and revoke them.
A token is a key you hand to a program. It has this format:
paper_k3m9x2ab_Q7wLc2…(40 characters)paper_marks it as a Paper token. Tools that look for leaked secrets recognize this prefix.- The 8 characters in the middle identify the token. They show up in the token list, so you know which is which.
- The last 40 are the secret. The server keeps only a digest (hash) of it, so not even Paper can show the token again. If you lose it, revoke it and create another.
The two kinds
| Secure (for AI) | Regular | |
|---|---|---|
| What for | Giving a vault to an AI to work on | Your own automations |
| What it reaches | An isolated copy of one vault | The real vaults, through Google Drive |
| Changes | Wait for your review | Take effect right away |
| Calendar and files | No | If you allow |
| Needs Google allowed for the API | No | Yes |
When in doubt, use secure. If the AI makes a mistake, the real vault stays intact.
Permissions
When creating a regular token, you choose:
| Permission | Options |
|---|---|
| Each vault | No access, Read, Read and edit |
| Protected pages | Hide (the token doesn't even know they exist) or Show only the title |
| "Paper" calendar | No access, Read events, Read and create events |
| Send files | Yes or no |
| Expiry | 7 days, 30 days, 90 days or no expiry |
Even with "Show only the title", the content of protected pages never leaves: the request answers 423.
The secure token has fixed permissions: it reads and edits only its own copy.
See how the token looks to the API
curl https://wire.ia.br/api/v1/me -H "Authorization: Bearer $PAPER_TOKEN"{
"conta": { "id": "3f2a…(32 characters)", "nome": "Ana" },
"token": {
"id": "k3m9x2ab",
"nome": "Task script",
"tipo": "normal",
"permissoes": {
"vaults": { "principal": "editar", "cmg2k1x9a4tz": "ler" },
"protegidas": "ocultar",
"agenda": "ler",
"anexos": false
},
"venceEm": "2026-11-01T12:00:00.000Z"
},
"limites": { "perMinute": 60, "perDay": 5000, "uploadsPerDay": 30, "uploadBytes": 10485760, "pageBytes": 1048576 },
"documentacao": "https://wire.ia.br/documentation/agents/raw.json"
}Field names and values are in Portuguese: tipo is seguro (secure) or normal (regular); vault access is ler (read) or editar (edit); protegidas is ocultar (hide) or titulo (title only); agenda is nenhum, ler or editar.
Keep it safe
- Keep it in an environment variable or a password manager. Never in public code, screenshots or group messages.
- One token per program. That way, revoking one doesn't take down the others.
- Give only the permissions the program needs.
Revoke
In Settings → Developer → Active tokens, tap Revoke. The token stops working on the next request. The list also shows when each token was last used and how many times.
A leaked token used for abuse leads to the ban of the account that owns it. If you suspect a leak, revoke it before anything else.