Security settings

What lives on the Security tab, who can reach each part of it, and what belongs to your account instead.

Three things live on the Security tab, and they have less in common than the grouping suggests.

SectionWhat it isWho can use it
TokensAPI tokens for the API, CLI, and MCP serverOwner and Admin
SAML SSOSign-in through your own identity providerOwner only
Tailscale on screensPutting your screens on your private networkOwner and Admin

API tokens

A token authenticates to the API, the CLI, and the MCP server, and carries the permissions of the account that created it.

It is shown once and never again. See API tokens.

SAML single sign-on

Enterprise, Owner only. See Single sign-on.

Tailscale on screens

Despite living under Security rather than Integrations, this is about what your devices can reach rather than what the dashboard connects to: it puts screens on your own Tailscale network so they can display internal dashboards and intranet pages.

ScreenlyOS only. See Reaching your private network.

What is not here

Passkeys and two-factor authentication are personal, under your account settings rather than the workspace. They are how you sign in, and they work across every workspace you belong to.

Privacy mode is per screen, on that screen’s Actions tab, not a workspace setting.

The full map is in Where settings live.

Type to search the documentation