Skip to content

Figma Token Table

Migrated from OAuth on 2026-05-07

This table previously stored Figma OAuth access_token / refresh_token material. The integration switched to per-user Personal Access Tokens (PAT). The table name is preserved for migration continuity; the columns now describe a single PAT per user.

Overview

Figma Personal Access Tokens keyed by cognito_sub (one row per user identity in this table).

Table Definition

Logical Name Physical Name Column Name Data Type Primary Key Relation Unique Nullable Default Value Remarks
Figma Token figma_token cognito_sub string โ—ฏ
personal_access_token string text in DB; AES-256 encrypted at rest
last_validated_at datetime โ—ฏ Last successful GET https://api.figma.com/v1/me (optional)ยน
created_at datetime
updated_at datetime
deleted_at datetime โ—ฏ
created_by string user:cognito_sub
updated_by string user:cognito_sub
deleted_by string user:cognito_sub โ—ฏ

ยน last_validated_at is optional and may be deferred to the implementation spec if the team prefers a minimal-change migration. The other columns are required.

Relations

  • created_by / updated_by / deleted_by โ†’ user.cognito_sub (standard audit)

Indexes

  • PRIMARY KEY (cognito_sub)
  • INDEX figma_token_deleted_at_idx (deleted_at)

Notes

  • personal_access_token stores a Figma Personal Access Token, encrypted at rest with AES-256.
  • PATs do not auto-refresh. When Figma returns 401/403, the user regenerates a PAT in Figma settings and re-registers it; the row is overwritten in place.
  • Token expiry is controlled by Figma (chosen by the user at PAT generation time); the backend does not track it. A GET /v1/me validity check at registration time is the only check this table records.
  • Removed columns from the prior OAuth schema: refresh_token, expiry_date. Their associated index figma_token_expiry_date_idx is also removed.