# Problem with token creation

**URL:** <https://developer.sailpoint.com/discuss/t/problem-with-token-creation/108713>\
**Category:** SHF Discussion and Questions\
**Tags:** identity-security-cloud\
**Created:** [April 7, 2025, 4:20pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-token-creation/108713 "2025-04-07T16:20:40Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![kdfreeman](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kdfreeman/32/22737_2.png) [@kdfreeman](https://developer.sailpoint.com/discuss/u/kdfreeman)\
**Post date:** [April 7, 2025, 6:06pm UTC](https://developer.sailpoint.com/discuss/t/problem-with-token-creation/108713/2 "2025-04-07T18:06:18Z")

</div>

Hi Salvatore,

You need to create Personal Access Token with necessary scopes and user level to access API. If you go with API token, they may not be able to access all api. Refer this thread.

> [@Difference between API Keys and Personal Access Token](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756):
>
> Dear all, If you ever have to use Client ID and Secret in a script, what whould you choose, API keys or Personal Access Token? For my part, I’ve read [this article](https://documentation.sailpoint.com/saas/help/common/api_keys.html) and still can’t answer the question. But, so far, I see one caveat for the Personal Access Token, is that we need to create a service account for it, meanwhile, no need for a specific user to manager API keys. Please correct me if I’m wrong. Thanks.

```auto
the API token with client credential grant type does not have a user linked to it. This type of token will not be able to call all the IDN REST endpoints. For example, the role revocation API end point /v3/access-requests will give a forbidden error while using the client credential as this end point excepts the call only from a valid user which makes sense from a audit and security standpoint.

The PAT token on the other hand is also of client credential grant type but associated to a user. The PAT associates the user that created the PAT to the generated access tokens, giving those tokens the same user level as the user that created it. So if you are an Admin user and you generate a PAT with `sp:scopes:all` , your PAT can access **almost** every API endpoint.

```

Thanks

---

_[View the full topic](https://developer.sailpoint.com/discuss/t/problem-with-token-creation/108713)._
