Auth tokens
Most of the time just run pipehero login — it opens your browser once and the CLI reuses that session. A token is for the cases where there's no browser to open: CI pipelines, headless servers, containers.
Generate one
In Settings, under CLI tokens, click Generate token. The value is shown once — copy it immediately, it won't be shown again. From then on Settings only shows its creation and last-used dates.
Use it
With the CLI:
pipehero start myapp --port 3000 --auth-token <token>
Or to skip OAuth when adding the remote MCP server in a headless environment:
claude mcp add --transport http pipehero https://mcp.pipehero.app/mcp \ --header "Authorization: Bearer <token>"
Revoke it
Tokens don't expire on their own. Click Revoke next to it in Settings when you're done with it — a revoked token is kept in the list (marked revoked) for reference, but stops working immediately.
FAQ
Do I need a token for everyday use?
No. pipehero login opens a browser once and reuses that session — that's enough for local development. A token is only for environments where a browser can't open, like CI or a headless server.
Where can I use a token, besides the CLI?
Anywhere the CLI's --auth-token flag works, and also to skip OAuth on the remote MCP server — pass it as an Authorization: Bearer header instead of approving in the browser.
Does a token expire?
Not automatically. It stays valid until you revoke it from Settings, so treat it like a password: store it as a CI secret, not in a committed file.
I lost the token value — now what?
The value is shown once, right after you generate it, and never again — Settings only shows its creation and last-used dates afterward. Generate a new one and revoke the old one.
Is a token tied to me or to the workspace?
The workspace. Any token generated under an org authenticates as that workspace, so it works the same way for a teammate's CI pipeline as it does for yours.