appsAdd
Create an app credential and return its JWT once in full.
The token authenticates the public GraphQL API and hosted MCP via x-app-token
(Authentication). Choose scope at creation: prefer a least-privilege user group;
use allowAllPermission: true only when full access is required.
Copy accessToken from the response immediately — it cannot be retrieved again. Never ship the JWT in client-side code or source control. Rotate with appsAdd (new) → disable → appsRemove (old).
Side effects: Creates the app row and a backing system user used for permission checks.
Errors: userGroupId is required unless allowAllPermission is true
Auth · x-app-token · required permission manageDeveloper
Related: apps, appsEdit, appsRemove, AppTokenResult
appsAdd(name: String, userGroupId: String, workspaceId: String, expireDate: Date, allowAllPermission: Boolean, noExpire: Boolean): AppTokenResultArguments
Display name for the Developer dashboard and apps search.
Strongly recommended for identifying credentials later.
User group that defines this app's permissions.
Required unless allowAllPermission is true.
Do not pass an empty string — omit the field when using allow-all.
Locked after creation.
Optional workspace id for multi-workspace tenants. Usually inherited from the authenticated context — set only when targeting a specific workspace.
Token expiry when noExpire is false or omitted.
Ignored when noExpire is true.
When true, grants full workspace permissions and userGroupId may be omitted.
Prefer a dedicated user group with least privilege for production.
Locked after creation.
When true, the JWT does not expire (still revoke via appsRemove).
When false or omitted, set expireDate for a finite lifetime.
Returns
Id of the newly created app (same as App._id).
Full JWT for the x-app-token header on public GraphQL and hosted MCP requests.
Shown in full once — treat like a password. Later App reads
expose only **** + last 4 characters.