# Access tokens

Source: https://wire.ia.br/documentation/en/api/tokens

> The two kinds of token, the permissions of each, and how to keep and revoke them.



A token is a key you hand to a program. It has this format:

```txt
paper_k3m9x2ab_Q7wLc2…(40 characters)
```

* `paper_` marks it as a Paper token. Tools that look for leaked secrets recognize this prefix.
* The 8 characters in the middle identify the token. They show up in the token list, so you know which is which.
* The last 40 are the secret. The server keeps only a digest (hash) of it, so not even Paper can show the token again. If you lose it, revoke it and create another.

## The two kinds [#the-two-kinds]

|                                  | Secure (for AI)                    | Regular                               |
| -------------------------------- | ---------------------------------- | ------------------------------------- |
| What for                         | Giving a vault to an AI to work on | Your own automations                  |
| What it reaches                  | An isolated copy of one vault      | The real vaults, through Google Drive |
| Changes                          | Wait for your review               | Take effect right away                |
| Calendar and files               | No                                 | If you allow                          |
| Needs Google allowed for the API | No                                 | Yes                                   |

When in doubt, use **secure**. If the AI makes a mistake, the real vault stays intact.

## Permissions [#permissions]

When creating a regular token, you choose:

| Permission       | Options                                                              |
| ---------------- | -------------------------------------------------------------------- |
| Each vault       | No access, Read, Read and edit                                       |
| Protected pages  | Hide (the token doesn't even know they exist) or Show only the title |
| "Paper" calendar | No access, Read events, Read and create events                       |
| Send files       | Yes or no                                                            |
| Expiry           | 7 days, 30 days, 90 days or no expiry                                |

Even with "Show only the title", the content of protected pages never leaves: the request answers `423`.

The secure token has fixed permissions: it reads and edits only its own copy.

## See how the token looks to the API [#see-how-the-token-looks-to-the-api]

```bash
curl https://wire.ia.br/api/v1/me -H "Authorization: Bearer $PAPER_TOKEN"
```

```json
{
  "conta": { "id": "3f2a…(32 characters)", "nome": "Ana" },
  "token": {
    "id": "k3m9x2ab",
    "nome": "Task script",
    "tipo": "normal",
    "permissoes": {
      "vaults": { "principal": "editar", "cmg2k1x9a4tz": "ler" },
      "protegidas": "ocultar",
      "agenda": "ler",
      "anexos": false
    },
    "venceEm": "2026-11-01T12:00:00.000Z"
  },
  "limites": { "perMinute": 60, "perDay": 5000, "uploadsPerDay": 30, "uploadBytes": 10485760, "pageBytes": 1048576 },
  "documentacao": "https://wire.ia.br/documentation/agents/raw.json"
}
```

Field names and values are in Portuguese: `tipo` is `seguro` (secure) or `normal` (regular); vault access is `ler` (read) or `editar` (edit); `protegidas` is `ocultar` (hide) or `titulo` (title only); `agenda` is `nenhum`, `ler` or `editar`.

## Keep it safe [#keep-it-safe]

* Keep it in an environment variable or a password manager. Never in public code, screenshots or group messages.
* One token per program. That way, revoking one doesn't take down the others.
* Give only the permissions the program needs.

## Revoke [#revoke]

In **Settings → Developer → Active tokens**, tap **Revoke**. The token stops working on the next request. The list also shows when each token was last used and how many times.

A leaked token used for abuse leads to the ban of the account that owns it. If you suspect a leak, revoke it before anything else.
