API tokens
Tokens are how scripts, the MCP server, and other clients authenticate to Galene without a browser session. They are per-user: each token works for that user’s whole account.
Creating a token
Section titled “Creating a token”In Settings → API, the API tokens section lists your tokens and lets you create and delete them:
- Enter a Name — anything that helps you remember where the token is used (e.g.
laptop,claude). - Choose a scope. Read (the default) can call the read API and MCP. Write can change data, but only after an administrator turns the write API on (it is off by default). A read token is rejected for writes.
- Press Create token.
- Copy the token from the page. It starts with
galene_and is shown only once — if you lose it, create a new one instead.
To revoke a token, press Delete next to it. There is no separate revoke step; deleting is revoking.
Treat tokens like passwords. Never commit them to a repo, paste them into chat, or share them. If one leaks, delete it and create a new one.
Using a token with the REST API
Section titled “Using a token with the REST API”Send the token as a bearer token on any /api/v1 request:
curl -H "Authorization: Bearer galene_…" http://localhost:3000/api/v1/summaryUnauthenticated requests get a JSON 401: Unauthorized. Authenticate with an API token (Authorization: Bearer <token>).
The full endpoint list is on the API & MCP page.
Using a token with the MCP server
Section titled “Using a token with the MCP server”Stdio reads the token from the environment:
{ "mcpServers": { "galene": { "command": "bun", "args": ["/path/to/galene/mcp/index.ts"], "env": { "GALENE_API_URL": "http://localhost:3000", "GALENE_API_TOKEN": "galene_…" } } }}GALENE_API_URL defaults to http://localhost:3000. GALENE_API_TOKEN is required for stdio.
HTTP MCP on the app (path /mcp) does not use that variable. Enable MCP in Settings → API (or set GALENE_ENABLE_MCP=1) and send the token on each request. See API & MCP.
- Tokens bypass two-factor authentication; the browser still asks for a TOTP code.
- Galene stores only a salted hash of each token, so it cannot show a token again — that is why it is shown exactly once, at creation.
Scopes
Section titled “Scopes”Each token is read or write. Existing tokens stay read. Read tokens, browser sessions, and the MCP server cannot call write endpoints. A write token receives 403 until an administrator enables the write API under Settings → API. The public demo rejects token creation and every write.