Skip to content
DocsUnitley Docs home

Tokens and security

How Unitley access tokens work: what they can do, how long they last, how to revoke them, and how Unitley protects your saved provider keys.

An access token lets an app such as Claude Code, Cursor or a script use Unitley as you. You create tokens on the Connect page, give each app its own, and revoke any of them at any time.

What a token can reach

Every call made with a token runs as you. Unitley works out whose account it is from the token alone, never from anything else in the request, and your data stays behind the same per-account rules as in the console. A token sees your bankroll, bet log and picks, and nobody else's.

A token stops working the moment it is revoked or expires, or if your account is banned or deleted.

No tool can create, list or revoke tokens. That happens only in the console, signed in, so an app cannot use one token to make another.

Read only or read and write

When you create a token you choose what it may do:

AccessWhat the app can do
Read onlyRead your data, look up odds, stats, injuries and weather, and run the calculators. It cannot change anything.
Read and writeEverything above, plus log_bet, settle_bet and save_recommendation.

Tick Let it log bets, settle them and save picks for read and write. Leave it clear unless the app needs it.

An app with a read-only token still sees the write tools in its tool list. If it calls one, it gets an insufficient_scope error telling you to create a token with write access. See Troubleshooting.

Create a token

On the Connect page, give the token a name (up to 64 characters, so you can tell your apps apart), choose its access, and pick when it expires: 30 days, 90 days, 180 days or 1 year. The default is 30 days, the shortest choice.

A few things are checked first:

  • Your account is set up. You need to have finished onboarding, including confirming your age and accepting the disclaimer on the welcome page. See Account setup.
  • Your session is live. A token outlasts the session that made it, so Unitley checks with the sign-in server before making one. If you have used Sign out everywhere since you signed in, sign in again first.
  • You are under the limits. You can have up to 25 working tokens. There is also a cap on how many tokens you can have on record, counting revoked and expired ones, and a limit on how many you can create in a short time.

Shown once

Unitley shows a new token once, right after you create it, and never again. It keeps only a hash of the token, which cannot be turned back into the token, and its first 12 characters so you can recognize it in the list. Until you hide it or leave the page, the setup snippets on the Connect page fill the token in for you.

Keep it like a password. Anyone who has it can use Unitley as you until it expires or you revoke it. If you lose it, create a new one and revoke the old one.

A Unitley token starts with unt_, which makes it easy to spot if one ends up somewhere it should not.

The token list

The Connect page lists every token with:

  • its name, and whether it is Active, Expired or Revoked;
  • its access, Read and write or Read only;
  • its prefix, when it was created, and when it expires or ended;
  • Last used, with the name the app gave itself if it connected over MCP, or Never.

Last used is updated at most once a minute per token, so it can lag a busy app by up to a minute. The app name is whatever the app reports, so treat it as a label, not proof of which app it was.

Revoked and expired tokens stay in the list for 90 days, then drop off.

Revoke a token

Click Revoke next to the token on the Connect page, then Revoke now to confirm. Anything using that token loses access on its next request. A revoked token stays revoked: it cannot be turned back on, so create a new one if you need access again.

To replace a token without a gap, create the new one, update the app with it, check that it works, then revoke the old one. Each app's guide has the steps.

Sign out everywhere

Sign out everywhere, near the end of Settings, does two things:

  1. It revokes every token that still works, so Claude and any other agent using one stops working at once. Expired tokens are left as they are.
  2. It signs you out of Unitley on every device, this one included.

A browser that was signed in elsewhere may keep loading pages for up to an hour, until its sign-in expires, but it cannot renew it and cannot create a token. After signing out everywhere, sign in again and create new tokens for the apps you still use.

What Unitley records

Tool calls made with a token are recorded with the tool's name, the token, the app's name and whether the call worked. The record never holds what the app sent or what the tool answered. These records are kept for 90 days.

Your AI provider keys

If you use the web analyst, you save your own Anthropic, OpenAI or OpenRouter key in Settings, and optionally a key for Jev. Unitley protects them this way:

  • Encrypted at rest with AES-256-GCM. Each key is sealed to your account and to its provider, so a copy moved onto another account, or filed under another provider, cannot be decrypted.
  • Never shown again. After you save a key, Unitley shows only its last 4 characters.
  • Checked before saving. For an Anthropic, OpenAI or OpenRouter key, Test and save asks the provider whether it accepts the key, with a call that costs nothing. A key the provider rejects is not saved. A key that could not be checked is saved and marked Not verified. Because the check spends nothing, it may not catch a provider account that is out of credit. A Jev key has no free check, so it shows as connected after Jev's first answer.
  • Removable. Remove deletes the saved key. Deleting your account deletes every saved key with it.

Usage on these keys is billed by the provider, on your own account with them.

Access tokens and provider keys are separate. Connecting Claude or another agent with a token does not need a provider key, and a token never gives an app your provider keys.

21+ · Gambling problem? Call 1-800-GAMBLER or visit ncpgambling.org

Unitley is an analysis tool, not a sportsbook: it takes no bets and holds no money. Nothing in these docs is a guarantee or financial advice. Only bet where it is legal for you. Unitley is not affiliated with the NFL, its teams, or any sportsbook.

©︎ 2026 Unitley · Analysis, not a guarantee.