For the complete documentation index, see llms.txt. This page is also available as Markdown.

Personal Access Tokens

Tabnine supports Personal Access Tokens (PATs) for non-interactive authentication for APIs, scripts and integrations that call Tabnine services.

Generating a PAT

In the Admin Console, go to Settings on the lefthand-side menu and select Access Tokens. Then click Generate Token.

Personal Access Token generation is not admin-only. Any user with a Tabnine account can create PATs by navigating to [TABNINE_URL]/app/settings/access-tokens.

Next, type in the name or purpose of the token, then select an expiration date option from the dropdown menu.

Under Token access, choose the permissions the token should have. Grant only what it needs:

  • API access — enable individual API areas (Organization, Usage metrics, Audit logs, License and permissions, Users and teams, User management, Team repositories, Invitations) and pick Read or Read + write for each.

  • CLI / Agent access — enable Tabnine CLI and agent capabilities (YOLO mode, Context Engine MCP, Coaching Guidelines MCP).

The token can't be generated until you select at least one access type. For the full list of areas and the endpoints they cover, see Token scopes.

YOLO mode lets the CLI auto-approve every tool call without review — grant it only for trusted automation. If your organization has turned YOLO off (AI Features → Restrict YOLO mode), the option is disabled here and any token still cannot use YOLO: the organization-wide setting always wins.

Copy the token value and store it securely. Tabnine will not display it again. Then press Close.

Using a PAT in API calls

Include the PAT as a bearer token in the Authorization header of your HTTP requests.

Example: cURL

Example: Node.js

Example: Tabnine CLI (headless / non-interactive mode)

Set your PAT as TABNINE_TOKEN, then run prompts with -p:

For more automation patterns, see Non-Interactive Mode.

Use the same pattern for any internal Tabnine API endpoint (admin automation, reporting, or integration scripts).

Access Token List

A list of all active tokens will display on the Access Tokens page, noting:

  • Status

  • Permissions (the scopes granted to the token; hover for the full list)

  • Creation Date

  • Expiration Date

  • The last time it was used (including noting if it is still “Never Used”)

Revoking Tokens

In the final column on the same list, you have the option to revoke the token’s access by pressing Revoke. This will also eliminate it from the list of tokens.

Last updated

Was this helpful?