Figma Token Table
Migrated from OAuth on 2026-05-07
This table previously stored Figma OAuth access_token / refresh_token material. The integration switched to per-user Personal Access Tokens (PAT). The table name is preserved for migration continuity; the columns now describe a single PAT per user.
Overview
Figma Personal Access Tokens keyed by cognito_sub (one row per user identity in this table).
Table Definition
| Logical Name | Physical Name | Column Name | Data Type | Primary Key | Relation | Unique | Nullable | Default Value | Remarks |
|---|---|---|---|---|---|---|---|---|---|
| Figma Token | figma_token | cognito_sub | string | โฏ | |||||
| personal_access_token | string | text in DB; AES-256 encrypted at rest |
|||||||
| last_validated_at | datetime | โฏ | Last successful GET https://api.figma.com/v1/me (optional)ยน |
||||||
| created_at | datetime | ||||||||
| updated_at | datetime | ||||||||
| deleted_at | datetime | โฏ | |||||||
| created_by | string | user:cognito_sub | |||||||
| updated_by | string | user:cognito_sub | |||||||
| deleted_by | string | user:cognito_sub | โฏ |
ยน last_validated_at is optional and may be deferred to the implementation spec if the team prefers a minimal-change migration. The other columns are required.
Relations
created_by/updated_by/deleted_byโuser.cognito_sub(standard audit)
Indexes
- PRIMARY KEY (cognito_sub)
- INDEX
figma_token_deleted_at_idx(deleted_at)
Notes
personal_access_tokenstores a Figma Personal Access Token, encrypted at rest with AES-256.- PATs do not auto-refresh. When Figma returns 401/403, the user regenerates a PAT in Figma settings and re-registers it; the row is overwritten in place.
- Token expiry is controlled by Figma (chosen by the user at PAT generation time); the backend does not track it. A
GET /v1/mevalidity check at registration time is the only check this table records. - Removed columns from the prior OAuth schema:
refresh_token,expiry_date. Their associated indexfigma_token_expiry_date_idxis also removed.