Project Service Tokens Guide
AVAILABLEGenerate, scope, and manage machine-to-machine credentials for backend microservices and autonomous agents in the Developer Portal.
- Portal Page:
/projects/[projectId]/service-tokens(e.g. http://localhost:3000/projects)
Rendering diagram...
graph TD
Create["Click + Create Service Token"] --> Config["Configure Name, Environment & Capabilities"]
Config --> SetTTL["Select Expiration (30d, 90d, Custom)"]
SetTTL --> Attribute["Optional: Attribute to Member"]
Attribute --> Issue["Generate & Copy nst_live_..."]
How to Create a Service Token #
- Open your target Project in the Developer Portal.
- In the project sidebar, select Service Tokens.
- Click the + Create Service Token button.
- Fill in the token configuration:
- Token Name: A descriptive label (e.g.
order-processing-worker). - Environment: Select
TestorProduction. - Capabilities: Choose allowed operations (
inference:chat,tools:execute,mcp:access). - Expiration (TTL): Select a duration (30 days, 90 days, or Never Expire).
- Member Attribution: Optionally link this token to an engineer for personal budget metering.
- Token Name: A descriptive label (e.g.
- Click Generate Token.
- Copy the issued token (
nst_live_...) immediately.
Revoking a Compromised Token #
If a token is exposed or no longer needed:
- Locate the token in the Service Tokens table.
- Click the Revoke action button.
- Confirm revocation. The token is immediately blocked across all gateway data planes.
Next Steps #
- Understand token mechanics: Project Service Tokens Concept
- API Reference: Service Tokens API