# The Unity Access Token

A **Unity Access Token** (UAT) is a personal credential that authenticates Registry uploads from the Unity editor. Paste it into Unity once on each machine you use to publish. You don't need a token to install packages.

## 1. Create an account

Create a free account at [visualscript.dev](https://visualscript.dev). Your published packages, lists, and likes belong to this account.

## 2. Copy your token

Go to [`Settings` &rarr; `API`](https://visualscript.dev/settings/api).

![Registry access to the Unity Access Token](assets/registry-uat.jpg)

The website issues a token with your account. Use these controls to manage it:

| Button | Does |
| :--- | :--- |
| **Copy** | Copies the token to your clipboard. |
| **Reveal** | Shows the token as readable text. |
| **Generate new** | Issues a fresh token and **invalidates the current one**. |

!!! warning "A leaked token can publish under your name"
    Treat the token like a password. Do not include it in screenshots, messages, bug reports, public repositories, or committed scripts. The Visual Script team does not need your token to provide support.

    If the token is exposed, press **Generate new** immediately. The website invalidates the exposed value.

## 3. Sign in from the Unity editor

Open the **Visual Script Settings** window from the **Visual Script** button in Unity's main toolbar or `Window` &rarr; `Visual Script` &rarr; `Settings`. Select the **Account** section.

1. Paste the token into the **Unity Access Token** field.
2. Press **Sign in**.

The message at the top changes to *You are authenticated*. The **Account settings** button then opens your account on the website.

Until you sign in, the section shows *Sign in with your Unity Access Token*. Select **Learn more** to open the website's token settings from step 2.

## Where the token is stored

Unity stores the token in its editor preferences for the current user and machine:

| Scope | Consequence |
| :--- | :--- |
| Outside the project | Version control does not include the token, and teammates do not inherit it. |
| One machine | Repeat the sign-in step on every machine you publish from. |
| Across editor sessions | Unity retains the token through editor restarts and project switches. |

**Sign out** clears it from that machine. It doesn't invalidate the token — the same string still works elsewhere.

## Generating a new token

Use **Generate new** on the website if the token may have leaked or you need to revoke existing editor sessions.

The old token stops working immediately. Sign in again with the new token on each machine you use to publish.

Existing packages, likes, and lists are unaffected because they belong to your account rather than the token.

## If sign-in fails

Use the message or behavior you see to choose the next check:

| Symptom | Likely cause |
| :--- | :--- |
| *Authentication error* on sign-in | The token was pasted with something missing or an extra space. Use **Copy** on the website rather than selecting it by hand. |
| A previously working token fails | The token may have been regenerated. Copy the current token and sign in again. |
| *You are not authenticated* when uploading | You're signed out on this machine. The dialog offers to open the **Account** section. |
| Nothing happens | Check that the editor can reach the internet. A proxy or offline mode blocks the request. |

## Where to go next

- **[Publishing](publishing.md)** — upload a script after you sign in.
- **[Contributing](contributing.md)** — decide what to publish and prepare its listing.
