Personal Access Tokens
Tabnine supports Personal Access Tokens (PATs) for non-interactive authentication for APIs, scripts and integrations that call Tabnine services.
Generating a PAT
In the Admin Console, go to Settings on the lefthand-side menu and select Access Tokens. Then click Generate Token.
Personal Access Token generation is not admin-only. Any user with a Tabnine account can create PATs by navigating to [TABNINE_URL]/app/settings/access-tokens.
Next, type in the name or purpose of the token, then select an expiration date option from the dropdown menu.
Under Token access, choose the permissions the token should have. Grant only what it needs:
API access — enable individual API areas (Organization, Usage metrics, Audit logs, License and permissions, Users and teams, User management, Team repositories, Invitations) and pick Read or Read + write for each.
CLI / Agent access — enable Tabnine CLI and agent capabilities (YOLO mode, Context Engine MCP, Coaching Guidelines MCP).
The token can't be generated until you select at least one access type. For the full list of areas and the endpoints they cover, see Token scopes.
YOLO mode lets the CLI auto-approve every tool call without review — grant it only for trusted automation. If your organization has turned YOLO off (AI Features → Restrict YOLO mode), the option is disabled here and any token still cannot use YOLO: the organization-wide setting always wins.

Copy the token value and store it securely. Tabnine will not display it again. Then press Close.
Using a PAT in API calls
Include the PAT as a bearer token in the Authorization header of your HTTP requests.
Example: cURL
Example: Node.js
Example: Tabnine CLI (headless / non-interactive mode)
Set your PAT as TABNINE_TOKEN, then run prompts with -p:
For more automation patterns, see Non-Interactive Mode.
Use the same pattern for any internal Tabnine API endpoint (admin automation, reporting, or integration scripts).
Access Token List
A list of all active tokens will display on the Access Tokens page, noting:
Status
Permissions (the scopes granted to the token; hover for the full list)
Creation Date
Expiration Date
The last time it was used (including noting if it is still “Never Used”)
Revoking Tokens
In the final column on the same list, you have the option to revoke the token’s access by pressing Revoke. This will also eliminate it from the list of tokens.
Last updated
Was this helpful?
