…
## Set up
-- **User (email)** and **Password**: your d2 login. They are kept in the plugin's settings on that device only.
+- **Give the plugin its own token, not your password.** On the project's **Settings → AI permissions → AI tokens** page (`/ai/tokens`), New token: a name (*Diesel Sync*), **Kind: Tool** — a token for a program, which works directly under its own name and mints nothing — a **Role** (`user`) and a **level** (`member` to read and write, `mod` for more), and **untick *Its changes to topics are drafts*** so a sync saves the topic itself. Put it on the project's line: `d2spec = d2t_…`. Every sync then reads as *you via diesel-sync*, so the history says which device and which program wrote a line, and your password is nowhere in the plugin's settings.
- **d2 projects**: one project per line, e.g. `d2spec`. Each gets a folder under the **Root folder** (`Diesel/d2spec`), and the first **Sync all** pulls its topics into it.
-- A line can carry a project's AI token instead (`d2spec = d2t_…`, from the project's Tokens page). A token's writes become drafts, so for editing, your login is the better choice.
+- **User (email)** and **Password**: your d2 login, the fallback for a project with no token on its line. It works as it always did, and a token is the better choice: it can't log you in anywhere, you can revoke it from the tokens page without changing your password, and what it writes is recorded as the plugin's rather than as you in person.
+- **Leave *Its changes to topics are drafts* ticked** and the plugin proposes instead of saving: a sync's push becomes a draft on your **Drafts** page and the topic stays as it was, so the next pull brings the old text back over your note. Fine for a vault you only read from; not what you want for editing. On the free plan a token's writes are always drafts, so there use your login for editing.
- **Sync d1 reactors**: turn it off if you only use d2.
…
## FAQ
-- **I get "HTTP 401".** Check the user and password, or the project's token. After one refusal the plugin stops calling that project until the next sync, so it doesn't lock your login.
+- **I get "HTTP 401".** Check the project's token, or the user and password. After one refusal the plugin stops calling that project until the next sync, so it doesn't lock your login. A token that was revoked, or that has expired, answers 401 too: make a new one and put it on the project's line — a tool token mints nothing and renews nothing, so there is no second credential to chase.
+- **My edits keep coming back as the old text.** The token's changes are drafts: the push went to your Drafts page and the topic never changed, so the next pull overwrites the note. Make a new token with *Its changes to topics are drafts* unticked — that setting is fixed once a token exists, and only its role can be changed later — or publish what is waiting on `/drafts`.
- **A note says "left alone (d1 sync is off)".** It's linked to an old dieselapps reactor. Turn **Sync d1 reactors** back on, or move the note out of the folder.
- **Can I sync another project's topics?** Only projects you list, with a login or token that can read them.
…