1. Click on `Access tokens` in the `User settings`:
-**If the existing token is a fine-grained PAT and you are not changing its boundaries or permissions:** next to the active token, select the vertical ellipsis (⋮) → **Rotate**. GitLab issues a new token with the same configuration, immediately deactivates the old one, and retains both for audit. Skip to step 12.
-**If the existing token is a fine-grained PAT and you are not changing its boundaries or permissions:** next to the active token, select the vertical ellipsis (⋮) → **Duplicate**, which will bring you to the page with most of the same configurations pre-filled. You need to manually adjust the token name and expiration date per your project requirement. The standard token lifespan is 1 year. Continue with step 8.
-**Otherwise** (legacy PAT, or you need to change a gPAT's scope): click the `Add new token` button and continue with step 8.