# Personal tokens

## What a personal token can do

A personal token lets a script or a service call the Teamhood API **on behalf of your account**.

A token can do exactly what you can do, in the organization where you created the token, and nothing more.

Tokens live in **Settings → Personal tokens**. [Open in Teamhood](https://app.teamhood.com/go/settings/personal-tokens)

## Creating and keeping a token

Give each token a name that says what uses it. The list then shows, for each token, when it was last used and when it expires.

The token's value is shown when it is created. Copy the value then, and treat it like a password afterwards. Never put a token value in a shared document, a ticket or a repository.

## Revoking a token

Delete a token the moment its integration is retired. Delete a token immediately if you think the value has leaked.

Deleting takes effect for every caller that holds that value, and no other token is affected. That is the reason to create one token per integration, rather than reusing a single token everywhere.

## Tokens and a lapsed organization

If an organization's subscription lapses, its personal tokens stop answering. When an integration goes silent all at once, check the subscription page before you blame the token. See [What happens when a subscription lapses](../../subscription/what-happens-when-a-subscription-lapses/).
