# All API tokens are now fully deletable

[date: 2025-08-27T20:59:04.524+02:00]

From now on, **all API tokens** — including the default non-editable tokens that are automatically created by DatoCMS — **can be deleted**.

Previously, default non-editable tokens (such as the read-only token) could not be removed. This change is a matter of security, giving you full control over your API tokens and allowing you to remove any unused or potentially exposed credentials.

💡 **Reminder:**  
If you delete a default non-editable token generated automatically, it cannot be recreated. However, you can always create a new one with the same or custom permissions.