# Permanent Access token

**URL:** <https://community.prismic.io/t/permanent-access-token/5623>\
**Category:** Developing with Prismic\
**Tags:** rest-api\
**Created:** [June 4, 2021, 3:46pm UTC](https://community.prismic.io/t/permanent-access-token/5623 "2021-06-04T15:46:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dan.parker](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/dan.parker/32/2232_2.png) [@dan.parker](https://community.prismic.io/u/dan.parker)\
**Post date:** [June 4, 2021, 3:46pm UTC](https://community.prismic.io/t/permanent-access-token/5623/1 "2021-06-04T15:46:20Z")

</div>

Hi there,

I'm trying to use the prismic rest api to implement a feature in my components of my next.js app.  
Our private repo requires an access token hit the api endpoint.  
In order to successfully hit the api from the component, I had to include the api endpoint and access token in my public runtime config. This means that the access token is visible from the browser. I'm not sure of a way around this. Can you tell me if the access token comes with any write permissions? If that's the case then we definitely don't want to expose it. Trying to understand what kind of vulnerability comes with exposing this token.  
Many thanks,  
Dan

---

<div class="post-metadata">

**Author:** ![Phil](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/phil/32/14_2.png) [@Phil](https://community.prismic.io/u/Phil)\
**Post date:** [June 4, 2021, 4:17pm UTC](https://community.prismic.io/t/permanent-access-token/5623/2 "2021-06-04T16:17:34Z")

</div>



---

<div class="post-metadata">

**Author:** ![Phil](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/phil/32/14_2.png) [@Phil](https://community.prismic.io/u/Phil)\
**Post date:** [June 4, 2021, 4:18pm UTC](https://community.prismic.io/t/permanent-access-token/5623/3 "2021-06-04T16:18:32Z")

</div>

Hi Dan,

This question has already been answered here:

> [@Access token permissions](https://community.prismic.io/t/access-token-permissions/2996):
>
> As we have an open-source project in Gatsby, which uses Prismic as CMS, the contributors cannot build the project without an access token. Does it safe to share an access token publicly? Does it provide only read permission or write too? Our goal there is only giving the ability to read and not write.

Thanks.

---

<div class="post-metadata">

**Author:** ![Phil](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/phil/32/14_2.png) [@Phil](https://community.prismic.io/u/Phil)\
**Post date:** [June 4, 2021, 4:18pm UTC](https://community.prismic.io/t/permanent-access-token/5623/4 "2021-06-04T16:18:40Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/system/32/1746_2.png) [@system](https://community.prismic.io/u/system)\
**Post date:** [December 9, 2021, 3:43pm UTC](https://community.prismic.io/t/permanent-access-token/5623/5 "2021-12-09T15:43:10Z")

</div>


