Manage secrets

API token hashing is enabled by default in InfluxDB OSS 2.9.0

Stronger token security: tokens are stored as hashes on disk, so a copy of the database file doesn’t expose usable tokens. Existing tokens are hashed on first startup and the original strings can’t be recovered afterward — capture any plaintext tokens you still need before you upgrade.

For more information, see Token hashing.

Secrets are key-value pairs that contain sensitive information you want to control access to, such as API keys, passwords, or certificates. There are two options for storing secrets with InfluxDB:

  • By default, secrets are Base64-encoded and stored in the InfluxDB embedded key value store, BoltDB.
  • You can also set up a Vault server to store secrets. For details, see Store secrets in Vault.


Was this page helpful?

Thank you for your feedback!