Skip to main content

Personal Access Tokens: connect MCP clients and call the API

Use a personal token to connect to FullEnrich MCP or call the API, with your own credit usage tracked.

Written by Greg Démogé

Personal Access Tokens (PATs) are personal tokens you can use in two ways: to connect any MCP client to FullEnrich without going through OAuth, or to call the FullEnrich API. They are made for setups where OAuth is not available or too heavy, like scripts, CI pipelines and custom integrations.

If your client supports OAuth (claude.ai, ChatGPT), use the standard MCP connector instead - it handles authentication automatically. PATs are for everything else.

What is a Personal Access Token?

A PAT is a long-lived token in the format fep_... that you create yourself from your FullEnrich settings.

A few things to know:

  • It's personal. The token is tied to you and to the workspace where you created it. Any action performed with it is done as you, in that workspace.

  • It works for MCP. Use it to connect Claude Code, Cursor or any MCP client. See Use it with MCP below for the setup.

  • It works for the API. Use it to call the FullEnrich API and track the credits you consume at a personal level. See Use it with the API below.

  • It can't be used to log into the app.

  • You can have several. Create one token per client (for example "Claude Code" and "CI script"), each with its own name, so you can track and revoke them individually.

Create a token

  1. Go to Settings => All Settings => Api Key & Tokens

  2. Click Generate new token

  3. Copy the token right away

⚠️ The token is shown only once. If you lose it, you can't retrieve it - just create a new one.

The token list shows each token's name, prefix, creation date & last used date.

Use it with MCP

Your PAT is used as a Bearer token on https://mcp.fullenrich.com/mcp.

Claude Code

bash

claude mcp add fullenrich https://mcp.fullenrich.com/mcp \
-t http \
-H "Authorization: Bearer fep_xxxxxxxx"

Cursor and other JSON-config clients

Add this to your mcp.json:

json

{
"mcpServers": {
"fullenrich": {
"url": "https://mcp.fullenrich.com/mcp",
"headers": {
"Authorization": "Bearer fep_xxxxxxxx"
}
}
}
}

Quick test with curl

bash

curl https://mcp.fullenrich.com/mcp \
-H "Authorization: Bearer fep_xxxxxxxx" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Note: the claude.ai web connector stays on OAuth - it doesn't support custom headers. PATs are meant for desktop, CLI, and script-based clients.

Use it with the API

Your PAT works exactly like an API key. Replace your usual API key with your PAT in the Authorization header:

Authorization: Bearer fep_xxxxxxxx

Everything else stays the same: same endpoints, same requests. See the API documentation for the full reference.

Credits consumed with your PAT are tracked at a personal level.

Revoke a token

  • Revoke: click on the Trash icon next to the token in the list. It stops working immediately and disappears from the list. This is irreversible.

If a token was exposed (accidental commit, screen share...), revoke it immediately and create a new one. In the worst case, a revoked token may remain valid for up to 5 minutes due to caching - after that, it's fully blocked.

Best practices

  1. One token per client. Don't reuse the same token in Claude Code and a CI script - that's what the name field is for.

  2. Store tokens as secrets (environment variables, secret manager) - never in plain text in a repo.

  3. Revoke any exposed token immediately, then create a new one.

  4. Check the "Last used" column from time to time and revoke tokens you no longer use.

Did this answer your question?