Deployment tokens allow command-line interface (CLI) tools, continuous integration (CI) pipelines, and deployment scripts to build, deploy, and manage your project automatically.
Using a deployment token avoids sharing personal user credentials or requiring active browser sessions for automated tasks.
What a deployment token can do
A deployment token provides access to a single project. With a token, external tools can:
- Trigger new deployments
- Read, create, update, or delete environment variables
- View or update branch-tracking rules
Create a separate token for each build pipeline or tool so you can revoke one without interrupting others.
WARNING: Anyone with a deployment token can deploy your project and view its environment variables. Always save tokens in a secure secret manager, never commit them to code repositories, and delete tokens immediately if exposed.
Generate a deployment token
Because monolayer displays full deployment tokens only once upon creation, make sure you have a password manager or secret store ready before generating a token.
Before you start
Prepare your secret manager or secure storage location to receive the new token.
- Click Projects in the global sidebar and select your project.
- Click Settings > Deployment Tokens in the project sidebar.
- Click Generate deployment token.
- Click the copy icon next to the token value.
- Save the token value in your secret manager. Confirm that the saved string begins with
deploy_token_. - Click Close.
Revoke a deployment token
Delete a token when an automated script no longer needs it or if a credential may have been exposed.
- If automated deployments must continue without interruption, create and test a new replacement token first.
- Locate the token row in the Deployment Tokens table.
- Click the trash icon in the actions column.
- Click Delete to confirm.
For complete interface details, see Deployment Tokens.