# Understanding token scope difference

**URL:** <https://discourse.jupyter.org/t/understanding-token-scope-difference/10467>\
**Category:** JupyterHub\
**Created:** [August 23, 2021, 9:24pm UTC](https://discourse.jupyter.org/t/understanding-token-scope-difference/10467 "2021-08-23T21:24:08Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![minrk](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/minrk/32/13_2.png) [@minrk](https://discourse.jupyter.org/u/minrk)\
**Post date:** [August 24, 2021, 7:15am UTC](https://discourse.jupyter.org/t/understanding-token-scope-difference/10467/3 "2021-08-24T07:15:29Z")

</div>

Thanks for testing this and giving feedback!

> I am trying to understand why is there a difference

There are two “whys”:

1. the direct reason is that they have a different ‘role’ (`token` for the default token role, and `server` for the server token) which in turn _may_ have different scopes (they do by default)
2. the reason those roles differ is that servers don’t usually need much permissions to function, so they’ve been restricted to just what hey need _by default_.

The relevant part of the [rbac docs](https://jupyterhub.readthedocs.io/en/latest/rbac/roles.html#roles) is the _default roles_.

> and how would I automatically set the JUPYTERHUB\_API\_TOKEN with the “full” scoped token?

These roles have _default_ scopes, but you can also override them if you want a different collection of scopes assigned to the roles. It sounds like you want the server token to have full permissions of the owning user, which is encapsulated in the `inherit` scope:

```python
c.JupyterHub.load_roles = [
 {
   'name': 'server',
   'scopes': ['inherit'],
 }
]

```

This gets the same permissions you would have with 1.x. Depending on what you are using it for, I’d recommend looking at the [available scopes](https://jupyterhub.readthedocs.io/en/latest/rbac/scopes.html#available-scopes) and grant _explicit_ permissions for the additional functionality you want instead of automatically assigning full permissions, but that’s up to you for what makes sense in your deployment.

I opened [this pr](https://github.com/jupyterhub/jupyterhub/pull/3581) to add some of these details and this example to the docs.

Extra note:

- Tokens issued via the UI are assigned the `token` role, but the REST API the page uses supports assigning arbitrary roles. This is not exposed in the UI yet, so only the default is used when you click the ‘token’ button

_ **EDIT:** changed ‘all’ to ‘inherit’, which was the name we ended up releasing with_

---

_[View the full topic](https://discourse.jupyter.org/t/understanding-token-scope-difference/10467)._
