Token export

Export one connection's tokens over the API, or every connection's tokens from org settings, and what that means for your OAuth apps.

Arc0 stores nothing you can't get back out. Every connection's tokens can be exported, either one at a time through the API or all at once from org settings — on every plan, including free.

Exporting one connection

curl https://api.arc0.ai/v1/connections/conn_z663h86fl3z2/export \
  -H "Authorization: Bearer $ARC0_API_KEY"

This needs a key with Full access — see API keys. Read-only and Connect-links-only keys can't call it, since a token export is functionally a credential handoff, not a read.

Exporting all connections

An org owner can export every connection across every project from Settings → General → Token export → Export all connection tokens. It's owner-only by design, since it hands out every user's live credentials in one file.

Response shape

GET /v1/connections/{id}/export
{
  "id": "conn_z663h86fl3z2",
  "app": "salesforce",
  "user": "u_8f2",
  "auth_kind": "oauth2",
  "access_token": "00D8c0000008cSs!AQ...",
  "refresh_token": "5Aep861TSXNCcOAB...",
  "expires_at": "2026-09-27T10:30:00Z",
  "granted_scopes": ["read", "write"]
}

For a basic or api_key connection, access_token and refresh_token are replaced by whatever credential the app actually uses — the same shape Arc0 stores internally.

Why your own OAuth apps keep working after export

Whether the exported tokens keep working depends on who registered the OAuth app that issued them — see OAuth apps:

  • Your own OAuth app. You already hold the client id and secret, because you put them in the app's Credentials tab yourself. Once you export the tokens, you can refresh them with your own credentials indefinitely — Arc0 being in the loop or not doesn't change anything you couldn't already do.
  • Arc0-managed. The tokens were issued to Arc0's own OAuth client. You get the current access and refresh token in the export, but refreshing them again requires a client secret only Arc0 holds. They'll keep working until the access token's own expiry, and after that you're back to calling Arc0.

If you're planning to export and self-host a connection long-term, bring your own OAuth app first.

Security notes

  • Treat an export like any other live credential — store it the way you'd store a production secret, not a config file.
  • Every export is written to the audit log, so you can see who exported what and when.
  • Exporting a connection doesn't revoke it in Arc0. If you want the token retired from Arc0's side too, call DELETE /v1/connections/{id} afterward.
  • An export doesn't require the user's involvement — it's a workspace-level action, gated by who holds the API key or the org-owner role, not by the connected user.

On this page