---
title: "Tokens and environments"
description: "Create, store, rotate, and revoke the build credentials for each project environment."
canonical_url: "https://docs.linguana.dev/docs/use-linguana/tokens-and-environments"
markdown_url: "https://docs.linguana.dev/docs/use-linguana/tokens-and-environments.md"
x_farming_labs_generated_preamble: true
agent:
  task: "Create and safely store an environment-scoped Linguana project token."
  outcome: "CI can authenticate a build and the secret never enters browser code."
  prerequisites:
    - "A project exists and the user has Owner or Admin permission."
  sideEffects:
    - "Creates a one-time-visible project credential."
  verification:
    - "A successful build updates the replacement token's Last used value."
  rollback:
    - "Revoke the new token after restoring the prior CI credential."
  failureModes:
    - symptom: "The build receives 401 or 403."
      resolution: "Confirm project/environment scope, revocation state, and compiler configuration."
---

# Tokens and environments
URL: /docs/use-linguana/tokens-and-environments
LLM index: /llms.txt
Description: Create, store, rotate, and revoke the build credentials for each project environment.
Related: /docs/reference/compiler

<!-- farming-labs:agent-contract:start -->
## Agent Contract

Task: Create and safely store an environment-scoped Linguana project token.
Outcome: CI can authenticate a build and the secret never enters browser code.

### Prerequisites

- A project exists and the user has Owner or Admin permission.

### Side Effects

- Creates a one-time-visible project credential.

### Verification

- A successful build updates the replacement token's Last used value.

### Rollback

- Revoke the new token after restoring the prior CI credential.

### Failure Modes

- The build receives 401 or 403. — Recovery: Confirm project/environment scope, revocation state, and compiler configuration.
<!-- farming-labs:agent-contract:end -->

# Tokens and environments

Create a project token for builds and CI. Keep it out of browser code.

## Create a token

1. Open **Tokens** and select the project and environment.
2. Choose **New token** and use a recognizable name such as `GitHub Actions`.
3. Copy the complete value immediately. Linguana stores only its hash and never shows the secret again.
4. Save it as `LINGUANA_PROJECT_TOKEN` in the matching CI environment.

```bash title="local shell"
export LINGUANA_PROJECT_TOKEN='lna_…'
```

Do not prefix it with `VITE_`, serialize it into client state, log it, or commit it to an environment file.

## Environment policy

Use development tokens for manifest upload and optional build-triggered development publishing. Keep production publishing in the dashboard’s explicit release workflow. A token is scoped to its project and environment; a correct-looking token from another environment should be rejected.

## Rotate safely

1. Create the replacement token.
2. Update CI and complete a successful authenticated build.
3. Confirm **Last used** changed for the replacement.
4. Revoke the old token.

<ExpectedResult>
Token lists show only name, prefix, creation time, last use, and revocation state. The complete secret is visible once.
</ExpectedResult>

<FailureGuide symptom="Manifest upload returns 401 or 403" cause="The token is missing, revoked, or scoped to another project/environment." check="Compare the selected dashboard environment with compiler projectId and environment, then inspect the token prefix and Last used value." />

## Next

[Connect hosted translations](/docs/getting-started/connect-your-app) using the token. For runtime delivery, use a browser-safe publishable key as described in [Show translated content](/docs/build-with-code/show-translated-content).

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
Docs-scoped sitemap: [/docs/sitemap.md](/docs/sitemap.md).
Well-known sitemap: [/.well-known/sitemap.md](/.well-known/sitemap.md).
