Access tokens
Create and revoke the personal access tokens the CLI and API use to reach a namespace.
A personal access token lets the Observer CLI, a CI/CD pipeline, or a script call SBOM Observer as you, without your sign-in. A token belongs to the namespace it was created in and only works there. It expires one year after creation.
Create a token
Open Access Tokens
Open the user menu in the lower-left corner and select Access Tokens. The Personal Access Tokens page lists your tokens with their expiry dates.
Create the token
Select Create token, give it a name that says where it will be used (for example "GitHub Actions, frontend"), and select Create token.
Copy the value
The token value is shown once, with its expiry date. Copy it into your secret store now; after the dialog closes it can't be shown again.
Use a token
The CLI reads the token from OBSERVER_TOKEN and the namespace from OBSERVER_NAMESPACE, which defaults to default. Set OBSERVER_NAMESPACE to the token's namespace if it has another name; the name is the part of the app URL after /workspace/. A token used on any other namespace is rejected.
export OBSERVER_TOKEN=<token>
export OBSERVER_NAMESPACE=<namespace> # only if it isn't "default"
observer upload my-app.cdx.jsonIn CI/CD, store it as a pipeline secret, never in the repository. See CI/CD integration.
Revoke a token
Select the token in the list, select Revoke token, and confirm. Revocation is permanent, and anything using the token loses access. Create the replacement first if a pipeline still depends on it.
Next steps
- CI/CD integration with a token stored as a secret
- CLI reference for every command that uses the token