Scoped personal access tokens are leaving alpha. Remove the pre-GA
framing
and update pages that assumed every token carries full account access.
- Personal Access Tokens guide: remove the public alpha / early access
admonition. Add a section on using a scoped token with the Supabase CLI:
the browser flow of `supabase login` creates a classic token, while
SUPABASE_ACCESS_TOKEN or `supabase login --token` uses a scoped one, and
commands that connect with the database password aren't limited by the
token's permissions.
- Management API introduction: replace "PATs carry the same privileges
as
your user account" with the scoped vs. classic distinction and link to
the
guide's permission tables.
- MCP guide: the CI setup now asks for a scoped token limited to the
connected project and links to the MCP tool permissions table.
- API keys guide: replace the internal "fine-grained token" permission
ID
with the names shown in the dashboard (API Keys, Read), and note that
`reveal=true` in the example also needs API Key Secrets (Read).
- Managing environments: recommend a scoped token for the GitHub Actions
deploy workflow.