marlow

Access tokens

What to create, and what to tick

One of the five needs a credential you make yourself. Two more accept one if you cannot authorise the app, and two are a button. Every permission here is the list the console shows as you paste the token, read from the same place.

GitHub

Only if you cannot authorise the app

Install the Marlow GitHub App on an account or organisation. Pick the repositories Marlow should see; webhooks for issues and PRs are configured automatically.

  1. 1Install the Marlow GitHub App instead, if you can — the button in Settings → Integrations does the whole thing, and an App's permissions are scoped to the repositories you pick rather than to everything you can see.
  2. 2For a token: GitHub → your avatar → Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token.
  3. 3Under Repository access, choose Only select repositories and pick the ones Marlow should work on. This is the setting the App gives you for free and a classic token cannot express at all.
  4. 4Set the repository permissions listed under Permissions to grant, then generate. The value is shown once — GitHub will not show it again.

Permissions to grant

  • Fine-grained → Repository access: the repos Marlow should work on
  • Contents: Read and write (clone + push branches)
  • Pull requests: Read and write (open PRs)
  • Workflows: Read and write — only if changes touch .github/workflows
  • …or a classic token with the repo scope (add workflow for CI files)

What Marlow does with it

  • Read account profile and list accessible repositories
  • Read repository contents, issues, and pull request metadata
  • Open and update pull requests with agent output
  • Post comments and check status updates on issues and PRs

A fine-grained token belongs to a person, inherits what that person can reach, and dies with their access. Marlow reports the failure; it cannot renew it.

A token owned by an organisation may need an owner to approve it before it works — GitHub shows it as pending, and calls fail until then.

Where the provider issues it: github.com/settings/personal-access-tokens. A menu that has moved is theirs to move — this page describes their product, and the link is the thing that stays true.

GitLab

A token is the only way in

Connect a GitLab group with an access token. gitlab.com or an instance you run — a self-managed instance is addressed by its base URL, and each one is a separate connection with its own token.

  1. 1Prefer a group access token over your own: it belongs to the group rather than to you, so it survives you leaving. GitLab → the group → Settings → Access tokens → Add new token.
  2. 2Give it the scopes and the role listed under Permissions to grant. The role decides what the scopes are allowed to do, so a token with api and the Guest role still cannot open a merge request.
  3. 3Choose an expiry. GitLab requires one and caps it at a year.
  4. 4Create, and copy the value. It is shown once, and it starts glpat-.
  5. 5For a self-managed instance, paste its base URL into the console's Instance URL field. Each instance is its own connection with its own token — a token belongs to the instance that issued it.

Permissions to grant

  • api — read and write projects, merge requests, pipelines and members
  • write_repository — push the branch a run builds

Developer at least, and Maintainer if Marlow should merge — the role the token inherits decides what its scopes are allowed to do.

What Marlow does with it

  • Read projects, branches, and files
  • Open and merge merge requests, and comment on them
  • Read pipeline status for a commit
  • Push branches over HTTPS

Nothing renews this. The failure arrives up to a year later as a push that stops working, so put the expiry date somewhere a person will see it.

A project access token works too, and reaches one project. A group token reaches every project in the group, including ones added after it was made.

Where the provider issues it: docs.gitlab.com/user/group/settings/group_access_tokens/. A menu that has moved is theirs to move — this page describes their product, and the link is the thing that stays true.

Linear

Only if you cannot authorise the app

Authorise Marlow against your Linear workspace. Issues sync automatically; PR links post back on the originating ticket.

  1. 1Authorise the app instead, if you can — the button in Settings → Integrations lets Marlow act as itself rather than as you.
  2. 2For a key: Linear → Settings → API → Personal API keys → Create key.
  3. 3Name it for where it is used, and copy the value.

Permissions to grant

  • A Linear personal API key inherits your full workspace access — no scope selection needed

What Marlow does with it

  • List teams and read issue queries
  • Read issues, labels, comments, and assignees
  • Subscribe to webhooks for new and updated issues
  • Post comments on an issue when a run finishes

A Linear personal API key carries your full workspace access — there is no scope selection to get wrong, and no way to narrow it.

Everything Marlow does will appear as you: comments, labels, state changes.

Where the provider issues it: linear.app/settings/api. A menu that has moved is theirs to move — this page describes their product, and the link is the thing that stays true.

Jira

No token to create

Authorise Marlow against your Jira workspace. Issues sync automatically; updates post back on the originating ticket.

  1. 1Nothing to create. Press Connect in Settings → Integrations and authorise Marlow against your site.
  2. 2Atlassian asks which site to grant, and the grant can be withdrawn at any time from your Atlassian account's Connected apps page.

What Marlow does with it

  • Read projects, issues, and assignees
  • Subscribe to webhooks for new and updated issues
  • Post comments on an issue when a run finishes
Slack

No token to create

Authorise Marlow in your Slack workspace. Records the workspace and its bot token — which workspace the chat service answers in is still set per deployment.

  1. 1Nothing to create. Press Connect in Settings → Integrations and install Marlow into the workspace.
  2. 2Slack lets an install complete with fewer permissions than were asked for. Marlow records the shortfall and the console says so, because the symptom otherwise arrives much later as one feature quietly not working.

What Marlow does with it

  • See messages that mention Marlow, and read the thread they are in
  • Post and update messages, and upload a run's log
  • List channels, to offer them in the notification picker
  • Receive the /marlow command

Start on Free

Start with one boring ticket.

Connect a repository and send it something you have been putting off. Set the gate to “open a pull request and stop” — the worst case is a branch you close.

No card required · nothing to cancel · read the FAQ