Feature Reference

Access Tokens

Create and manage Qualflare project access tokens (API keys) for authenticating the CLI, automated scripts, and integrations.

Reviewed by Qualflare Team

Access Tokens

Access tokens are project-scoped API keys used to authenticate the Qualflare CLI, automated scripts, integrations, and AI coding agents over MCP.

What a token may do is decided by the project role of the person who created it, checked on every request: a Viewer's token can read, an Editor's token can also create and update. Lowering or removing that person's role takes effect immediately on the tokens they created.

Accessing Tokens

Go to Project Settings → Access Tokens to manage your project's tokens.

Creating a Token

  1. Click New Token
  2. Enter a descriptive name (e.g., "GitHub Actions", "Local Dev")
  3. Optionally set an expiration date
  4. Click Create
  5. Copy the token immediately — it is only shown once after creation

Access tokens are only displayed once at creation. Store it securely in a password manager or as an encrypted CI/CD secret immediately.

Token Fields

FieldDescription
NameA label to identify the token's purpose
CreatedDate the token was created
ExpiresExpiration date (if set), or "Never"
StatusActive or Revoked
Last UsedLast time the token was used to make an API call

Revoking a Token

Click the Revoke button next to a token to immediately invalidate it. Revoked tokens cannot be restored — create a new token if needed.

Using Tokens with the CLI

Save the token under a local identifier with qf login, then prefix your commands with that identifier:

# Save the token locally
qf login myapp qf_your_token_here

# Upload test results
qf myapp collect results.xml

# In CI/CD — log in with --force to skip the interactive prompt
qf login ci "$QF_TOKEN" --force
qf ci collect test-results/*.xml

See CLI Configuration for details on the identifier model, credentials file location, and available options.

Using Tokens with a Coding Agent

The same token connects an AI coding agent to Qualflare over MCP — no separate key:

claude mcp add --transport http qualflare https://api.qualflare.com/mcp \
  --header "Authorization: Bearer qf_your_token_here"

See Connect a coding agent for other clients, and MCP Server for every tool an agent can call.

Security Best Practices

  • Use one token per environment — separate tokens for local dev, staging, and production
  • Store in CI secrets — never commit tokens to source code
  • Set expiration dates — rotate tokens regularly (e.g., every 90 days)
  • Revoke unused tokens — clean up tokens for tools or environments no longer in use
  • Use descriptive names — "GitHub Actions — Production" is clearer than "key1"

See Also