Studio

Pairing codes

Short-lived codes exchange for a hashed, scoped token.

Connect Studio creates a pairing code that expires quickly. The plugin exchanges the code for a token bound to one project and one user.

The token is stored hashed. It can be revoked from the workspace. There is no permanent master token and no shared studio secret.

If a code expires, make a new one. Old codes stop working. Stolen tokens can only touch the project they were issued for.