Personal access token scopes
Token creation offers these scope pairs:
New keys start with the available read scopes selected. Remove any read area the client does not need. Add a write scope only for an intended write workflow.
Write behavior
An OAuth connection receives the same capability scope as the in-app Assistant after the user explicitly grants read and write access. Floral still checks active membership, role, feature permissions, Work access, and workspace ownership on every call. Connections created before write access was introduced remain read-only until the user reconnects and reviews the updated consent. Use OAuth only with a client you trust to follow the user’s intent and handle confirmation appropriately. Disconnect the client immediately if its behavior is unexpected. Use a personal access token when you need narrower credential scopes. Create a separate key per client, give it a short expiry, and avoid “no expiry” unless the environment has its own rotation process. Test with read-only scopes first.Credential handling
- Store the full key in the client’s secret storage.
- Never put it in source control, a prompt, a Source, or ordinary logs.
- Revoke it immediately if it appears in copied output or screenshots.
- Disconnect unused OAuth clients and revoke keys for retired devices.
