> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stora.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage access

> Manage scopes, extend Access Tokens, disable or revoke credentials, and terminate a developer connection to a Stora account.

After you [connect an account](/2025-09/guides/connect-account), use **Connected accounts** in the [Developer Portal](https://developer.stora.co) to manage its API credentials.

Credential management requires an active account connection and Public API access. Disabling, enabling, revoking, and removing credentials requires an admin role in your developer company. Revoking a real account connection also requires an admin role.

<Note>
  The **Access tokens** list contains tokens you create in the portal. Tokens your backend obtains from an **OAuth Client** are separate, short-lived tokens. To stop access through an OAuth Client, disable or revoke the client itself.
</Note>

## Change scopes

1. Open the account under **Connected accounts**.
2. Find the Access Token or OAuth Client and open **Actions** → **Manage scopes**.
3. Select only the scopes your integration needs.
4. Click **Save changes**.

The available scopes depend on the Stora account. See [Authorization](/2025-09/guides/authorization) for the scope list.

For an OAuth Client, request a new token with the required scopes after saving. Changing the client does not add permissions to an already-issued token. Existing tokens retain their issued scopes; do not rely on a scope edit to stop their access immediately. Disable or revoke the client if you need to stop access.

For a portal-created Access Token, the saved scopes apply to that token. You do not need a token exchange or a new token string.

Stora emails the connected account owners when you change credential scopes. Name-only edits do not send an email.

## Extend an Access Token

Portal-created Access Tokens expire. At creation, you can choose **7**, **30**, or **60 days**. The default is 30 days.

To extend a token that has not expired or been revoked:

1. Open the account under **Connected accounts**.
2. Find the token under **Access tokens**.
3. Open **Actions** → **Extend by 10 days**.

Each extension adds 10 days to the expiry date. You can extend the total lifetime up to 120 days from creation. The action is unavailable when another extension would exceed that limit.

You cannot extend an expired or revoked token. Create a replacement if you still need access.

<Tip>
  Use Access Tokens for one-time scripts or short-lived AI-agent tasks. For an ongoing integration, use an [OAuth Client](/2025-09/guides/managed-account-authentication#use-an-oauth-client) so your backend can obtain new tokens automatically. OAuth-issued tokens expire after 2 hours; the portal's extension action does not apply to them.
</Tip>

## Disable or enable a credential

Use **Disable** when you need to pause access without permanently revoking the credential.

1. Open the account under **Connected accounts**.
2. Find the Access Token or OAuth Client.
3. Open **Actions** → **Disable** and confirm.

| Credential | Effect of disabling |
| - | - |
| Access Token | API requests using the token are no longer authorised. |
| OAuth Client | The client cannot obtain new tokens, and API requests using its already-issued tokens are no longer authorised. |

To restore access, open **Actions** → **Enable**. Enabling does not extend a token's expiry or restore a revoked token. An OAuth Client's previously issued tokens may work again if they are still valid, unexpired, and not revoked.

Stora emails the account owners when you disable or enable a credential.

## Revoke or remove a credential

Use **Revoke** when a credential is no longer needed or has been exposed.

1. Open the account under **Connected accounts**.
2. Find the Access Token or OAuth Client.
3. Open **Actions** → **Revoke** and confirm.

Revocation is permanent: you cannot enable the credential again. Revoking an OAuth Client prevents new token exchanges and API access through its existing tokens. Create a new credential if you need to restore access.

After revocation, **Actions** → **Remove** removes the credential from the portal list. You can also remove an expired Access Token. Remove an OAuth Client only after revoking it.

<Warning>
  If a token or client secret is exposed, revoke the affected credential rather than extending it or changing its scopes. Create a replacement through [API credentials](/2025-09/guides/managed-account-authentication) and update your backend's protected configuration.
</Warning>

## Terminate an account connection

Revoking the account connection stops your developer company from managing that account's credentials. It is different from revoking the credentials themselves.

<Warning>
  Revoking a connection does not automatically stop existing credentials or webhook deliveries. Decide which credentials and webhook endpoints should remain active before terminating the relationship.
</Warning>

### From the Developer Portal

An admin in your developer company can:

1. Open the real account under **Connected accounts**.
2. Click **Revoke connection**.
3. Confirm **Revoke connection** in the dialog.

Existing credentials and webhook endpoints remain active unless they are disabled, revoked, or otherwise become unavailable. If access should stop, disable or revoke the credentials and disable webhook endpoints before revoking the connection. After revocation, the Stora account manages them in its back office; your developer company can no longer manage them in the portal.

Test-operator connections cannot be revoked through this flow.

### From the Stora account

A Stora staff member with the **Revoke developer company connections** permission can:

1. Open **Connected developers** in the Stora account's settings.
2. Find the developer company and click **Revoke**.
3. Review the OAuth Clients, Access Tokens, and webhook endpoints on the revocation screen.
4. Select the **Disable** checkboxes for credentials and endpoints that should stop working.
5. Click **Revoke connection**.

The screen preselects active OAuth Clients, active Access Tokens, and enabled webhook endpoints. Selected items are disabled; unselected items keep working. Disabling is not permanent credential revocation.

### Restore developer management

Ask an authorised Stora staff member to [approve an invitation again](/2025-09/guides/connect-account#connect-a-stora-account). This reactivates the existing connection and restores management of its credentials and webhook endpoints.

Reaccepting the connection does not enable disabled credentials, undo credential revocation, or extend token expiry. Review each credential's status before resuming the integration.

## If Public API access becomes unavailable

If the account loses Public API access, its API credentials become unavailable and the Developer Portal stops allowing credential and webhook management. Restoring the account's Public API access restores management for an active connection.

Credential expiry, disabling, and revocation still apply. Restoring Public API access does not replace expired or revoked credentials.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.