HOOKFISH_API_KEY can access every resource. Give applications named,
expiring broker tokens instead.
Exact paths and namespaces
/** when you intend to grant descendants. Paths are canonical
slash-delimited identifiers up to 768 characters.
Mint a token
user/personal/gmail/mcp. Grant
user/personal/** only if the service needs that subtree.
For a multi-tenant application, begin every connection and secret path with a
tenant prefix such as organizations/acme. Mint tokens against that same
prefix so a credential for one tenant cannot address another tenant’s paths.
Revoke a name with DELETE /api/admin/tokens/{name}. This revokes the named
token, every token delegated from it, and all deeper descendants. Unrelated
token grant trees remain active. Rotating the root key invalidates all scoped
tokens because it signs them.