Gatana logoGatana Docs

Clients & API Keys

See and control everything that can reach your Gatana, from connected OAuth clients to personal access tokens

Introduction

Clients & API Keys in the left sidebar lists everything that can reach Gatana as you, in three tables:

  • OAuth clients: apps that signed in through OAuth, such as Claude Desktop, Cursor, or the ChatGPT connectors. A client appears here automatically once it has signed in; there is nothing to register.
  • Federated clients: apps that reach Gatana with an access token from your organization's own identity provider, through OIDC Access Token Trust. One appears here automatically at its first request.
  • Personal access tokens: static secrets you create yourself and paste into a client that cannot sign in on its own.

Each is revoked differently: an OAuth client is disconnected, a token is deleted, and a federated client is revoked at your identity provider, since Gatana does not issue its token. Everything on this page is yours alone. Each user sees and manages only their own connections and tokens.

Connected Clients

Each row shows the client's name and version, what kind of client it is (CLI, desktop app, web app, or trusted IdP token), the profiles you attached to it, when it last made a request, and when it connected.

Client names are self-reported

A client chooses what to call itself, both when it registers and over MCP. The name is a label for you to recognize the connection by. It never decides what the client can access.

Renaming a Connection

Click Edit on the row and give the connection a name of your own. This is useful for telling two connections from the same app apart, for example Claude Code on your laptop and Claude Code on a server. Leave the name empty to keep showing the name the client reports.

Attaching Profiles

Click Edit on the row and select one or more profiles. The profiles are applied on every request that client makes, on top of the profiles you already hold, just like profiles on a personal access token. See Applying Profiles for what a profile can do, including narrowing a client down with a restrictive profile.

Disconnecting a Client

Click Revoke on the row. The client loses access immediately and has to sign in again to come back. Any profiles you attached to it are forgotten.

Inactive Clients

An OAuth client is marked Inactive when it no longer holds a refresh token to renew its access with. It will have to sign in again the next time it connects. Disconnect it if you do not expect it back.

Federated Clients

A federated client is an app that never signed in through Gatana. It authenticates with an access token issued by your identity provider, which Gatana accepts through OIDC Access Token Trust. The row is identified by the client ID the token names.

Renaming and attaching profiles work the same as for OAuth clients. There is no Revoke button: Gatana did not issue the token, so access is taken away in your identity provider. A federated client is marked Inactive after 30 days without a request.

Seeing What a Client Did

The Logs button on a row opens the audit log already filtered to that client, so you can see every call it made.

Personal Access Tokens

Create a token with New Token. Each row lets you reveal and copy the token value, shows the profiles assigned to it, when it was last used, and when it was created.

  • Connect shows ready-made configuration for common clients (Claude Code, VS Code, Cursor, and others) with the URL and the token already filled in. See MCP Authorization for the general shape.
  • Logs opens the audit log filtered to calls made with that token.
  • Edit renames the token or changes its profiles.
  • Delete removes the token. Anything still using it stops working at once.

Personal access tokens for service accounts are managed on the account's detail page under People & Accounts, by organization owners.

On this page