---
title: Service tokens
description: Learn more about service tokens on your Knock account and how they authenticate the Management API, CLI, and MCP server.
section: Developer tools
---

A Knock account service token authenticates requests to the Knock [Management API](/developer-tools/management-api), [CLI](/developer-tools/knock-cli), and [MCP server](/ai/mcp-server) for resources under your Knock account.

Service tokens always start with `knock_st_` and are different from your Knock API keys as they authenticate requests to the Knock Management API **only**.

<Callout
  type="alert"
  title="Note:"
  text={
    <>
      only account owners or admins have the privilege to generate (or revoke)
      service tokens. Service tokens will inherit the privilege of the owner or
      the admin that creates the service token, and therefore have full access
      to the management API.
    </>
  }
/>

## Generating a new service token

To use the Management API, CLI, or MCP server, you will first need to generate a service token and use it as a means of authentication.

To generate a service token, from the dashboard go to "Settings," select the "Service tokens" tab, and click the "+ New token" button. Then, provide a name for the token and click "generate" to view and save your newly generated service token.

<Callout
  type="alert"
  text={
    <>
      Note: once generated,{" "}
      <strong>
        you cannot see a service token again from the Knock dashboard,
      </strong>{" "}
      so be sure to copy it to a secure location.
    </>
  }
/>

## Revoking a service token

Service tokens can be revoked under the three-dot menu and by clicking on "Delete token." Deleting a token will **immediately** revoke its ability to be used against the Knock Management API, CLI, and MCP server.

## Frequently asked questions

<AccordionGroup>
  <Accordion
    title="Can I use a Knock service token against the Knock API?"
    anchorSlug="faq-service-token-with-knock-api"
  >
    No, a service token can only be used against the Knock Management API, CLI,
    and MCP server, not the Knock API.
  </Accordion>
  <Accordion
    title="Can I use a service token with the MCP server?"
    anchorSlug="faq-service-token-with-mcp-server"
  >
    Yes. Pass the token as a bearer credential in your MCP client config. See
    [authenticate with a service
    token](/ai/mcp-server#authenticate-with-a-service-token).
  </Accordion>
  <Accordion
    title="How can I know which changes were made by a specific service token?"
    anchorSlug="faq-attributing-changes-to-service-token"
  >
    Changes made via the Management API will appear as audit logs, similar to
    changes made manually in the dashboard, but attributing the service token
    used to make the change as the author. In addition, internally we audit
    requests and tie them back to a corresponding service token. If you need
    further help understanding which request originated from a service token,
    please [contact our support team](mailto:support@knock.app).
  </Accordion>
</AccordionGroup>
