create_project_token
Mint a PROJECT-scoped API token for a project you own, so an agent can bootstrap a fresh project without the panel (create_project → create_project_token → configure). Attenuated by design: the scopes must be a subset of THIS token's own grant (read is always included), expiry is mandatory (1–90 ...
This record as markdown: /tools/dev-echorelay-management/create-project-token.md
What create_project_token does on EchoRelay
AI agents use create_project_token to create or update resources in EchoRelay, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your EchoRelay environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
slug | string | Yes | The slug of a project you own. |
label | string | Yes | Human-readable token label (1–100 chars). |
scopes | array | — | Scopes for the minted token — must be a subset of this token's own scopes. `read` is always granted. Default: read + config. |
expiresInDays | integer | — | Days until the minted token expires. Default 30. API-minted tokens always expire. |
Parameters from the server's own tool schema.
Why create_project_token is rated Medium
This tool creates new API tokens, which is a write operation that modifies the credential state of a project. While tokens are security-sensitive and their creation could enable unauthorized access if misused by an agent, the tool itself has built-in attenuation (scope restrictions, mandatory expiry, no self-minting). It does not execute arbitrary code, delete data, or move money.
From the tool's definition Tool description states: 'Mint a PROJECT-scoped API token' and 'Returns the plaintext exactly once; only its hash is stored.' These are creational actions that generate and persist security credentials.
Attacks that exploit this kind of access
The rule that runs create_project_token safely
PolicyLayer is an MCP gateway: it sits between your AI agents and EchoRelay, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_project_token, this is the rule to start with:
create_project_token stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect EchoRelay, apply this rule, and every create_project_token call is checked against it from then on.
Questions about create_project_token
Mint a PROJECT-scoped API token for a project you own, so an agent can bootstrap a fresh project without the panel (create_project → create_project_token → configure). Attenuated by design: the scopes must be a subset of THIS token's own grant (read is always included), expiry is mandatory (1–90 days, default 30, never "never"), and the minted token — being project-scoped — can never mint tokens itself. Requires an ACCOUNT-scoped token and the config scope. Returns the plaintext exactly once; only its hash is stored. It is categorised as a Write tool in the EchoRelay MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
create_project_token accepts 4 parameters: slug, label, scopes, expiresInDays. Required: slug, label. The full parameter table on this page comes from the server's own tool schema.
Register the EchoRelay MCP server in PolicyLayer and add a rule for create_project_token: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches EchoRelay. Nothing to install.
create_project_token is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_project_token rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_project_token. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_project_token is provided by the EchoRelay MCP server (https://mcp.echorelay.dev). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on EchoRelay, and thousands of servers like it.
This server
Across the catalogue