IntegrationsAccess Tokens & Connected Apps

Access Tokens & Connected Apps

Control which AI assistants and scripts can work with your PanelWave account — approve connections, choose permissions, create personal access tokens, and disconnect apps.

Every AI assistant or script that works with your PanelWave account shows up in Profile → Connected apps & access tokens. From there you can see what has access, create tokens, and take access away again.

There are two kinds of access:

Connected appPersonal access token
How it is createdYou sign in from the app and click AllowYou create it in PanelWave and paste it into the app
Typical useclaude.ai, ChatGPT, Claude Code, CursorThe local bridge, scripts, CI jobs
LifetimeUntil you disconnect it30 to 365 days, then it expires
How it endsDisconnectRevoke, or expiry

Both act as you. They can only reach works your teams can reach, and your team role and plan limits apply as in the editor. Permissions narrow this further.

Permissions

A connection or token only gets the permissions you choose. An assistant doesn't even see tools outside them.

PermissionLets the assistant
works:readRead your works: structure, panels, characters, variables, graph, validation reports and translations.
works:writeCreate, change, reorder and delete works, chapters, pages, panels, balloons, hotspots, characters, variables and graph edges.
assets:readList your uploaded images, videos and audio and view their thumbnails.
assets:writeUpload, replace, organise and delete assets and attach artwork to panels.
localization:writeAdd languages, edit translations and start machine translation or text-to-speech.
publishRun validation fixes, publish previews and releases, and roll back.
team:readSee your teams, plan limits and credit balance.
analytics:readRead reader analytics of your works. Not selected by default.

For an assistant that should only look and advise, grant works:read and assets:read. Add publish only if you want the assistant to publish for you.

If an assistant later needs a permission you didn't grant, it tells you which one. Some apps then offer to sign in again with the wider set.

Approving a connection

When an app connects with sign-in, PanelWave opens the page Connect an app to PanelWave. Sign in first if needed, including your two-factor code.

Check who is asking

The page shows the app's name and the address it sends you back to. A yellow note appears when the app runs on your own computer, or when PanelWave hasn't verified the app. Only continue if you started this connection yourself.

Choose the permissions

Under … would like to: each requested permission has a checkbox. Untick anything you don't want the app to have.

Allow or deny

Click Allow to connect, or Deny to send the app away without access.

The app then appears under Connected apps with its permissions, when it was connected and when it was last used.

Creating a personal access token

Start a new token

Open Profile → Connected apps & access tokens and click New access token.

Name it and choose permissions

Give it a Name you will recognise later, such as "Claude Code on my laptop". Under What may the token do?, the usual permissions are pre-selected; untick what the tool doesn't need.

Choose when it expires

Under Expires after, pick 30, 90, 180 or 365 days. The default is 90 days.

Copy the token

Click Create token. The token starts with pw_pat_ and is shown only once. Copy it, along with the ready-made setup lines for Claude Code and the local bridge, then click Done.

You can have up to 25 active tokens. The list shows each token's first characters, when it was created, when it expires, and when it was last used.

Treat a token like a password. Don't paste it into chats, share it, or commit it to a code repository. If a token may have leaked, revoke it right away.

Disconnecting apps and revoking tokens

  • Connected app: click Disconnect next to it and confirm.
  • Token: click Revoke next to it and confirm.

The app or token loses access within a minute. Signing out of PanelWave doesn't end these connections. Some events end them automatically:

  • Changing your password revokes all your tokens and disconnects all apps.
  • Account suspension by PanelWave, or when a platform operator signs out all your sessions, does the same.