Create and manage API tokens
One hf_ token authenticates the REST API, the MCP server, and the editing plugins. Create, scope, and revoke them under Settings → API & MCP.
One hf_ token opens all three programmatic doors into HoldFast: the REST API, the MCP server, and editing plugins like Premiere Pro. Tokens live in Settings → API & MCP, and creating one is an admin action.
Create a token
- Open Settings → API & MCP and click + New Token.
- Give it a Token Name that says where it will live: Claude Code, Cursor, CI.
- Pick a Scope: Full API or Plugin (NLE).
- Set an optional Expiration date, then click Create.
The token starts with hf_ and is shown exactly once. Copy it into the tool that will use it before dismissing the banner; from then on, the table shows only the first few characters.
Create a scoped hf_ token in Settings → API & MCP.
Pick the right scope
- Full API reaches everything the REST API and the MCP server expose, including the intelligence tools. Requires Pro.
- Plugin (NLE) covers what the editing plugins need: uploads plus comment and marker sync. It cannot use the intelligence tools, and it is the one scope a Free workspace can create.
A token also inherits the role of whoever created it. A token made by a sales-role user reaches reels and analytics only, whatever its scope: the same wall the sales role meets in the app.
Revoke and audit
Click Revoke next to any token to shut it off. Revocation is immediate: the next request carrying that token gets a 401. The table tracks Created and Last Used for every token, which makes stale ones obvious, and a token past its expiration date is rejected automatically. If a token leaks, revoke it and mint a replacement; there is no way to re-display the original.
Questions
I lost my token. Can I see it again?
No. The full token is shown once, when it is created; the table keeps only the prefix. Revoke the lost one, create a replacement, and update whatever was using it.
Who can create tokens?
Workspace admins. Tokens grant programmatic access to the whole workspace, so creating and revoking them is an admin action.
What can a token created by a sales-role user do?
Reels and analytics only. A token carries the role of the person who created it, so the sales wall applies to the token exactly as it applies in the app.
Ready to try it?
Host video, collect frame-accurate review, and see who's watching. Free to start.
Start free