Manage API tokens
API tokens authenticate requests to the Telegraf Controller API and Telegraf agent connections. Use tokens to authorize Telegraf agents, heartbeat requests, and external API clients.
API tokens are separate from user sign-in. To configure how users sign in to Telegraf Controller, see Authentication.
Token format
All API tokens use the tc-apiv1_ prefix followed by 64 lowercase
hexadecimal characters, making them easy to identify in configuration files
and scripts.
The full token value is displayed only once at the time of creation and cannot be retrieved later. Copy and store the token in a secure location immediately after creating it.
Raw token strings are not stored
Tokens are stored as a cryptographic hash. The original value is never saved. If you lose a token, you must revoke it and create a new one.
Token sources
Every token records where its value came from:
| Source | UI label | Origin |
|---|---|---|
system | System-generated | Telegraf Controller generated the value. This is the default. |
user | User-provided | A client supplied the raw value. See Use pre-shared tokens. |
bootstrap | Env/flag-provided | Provisioned from OWNER_TOKEN or --owner-token at startup. See Bootstrap an owner token. |
The source is set at creation and never changes.
Token permissions
Each token is scoped to a specific user. Token permissions are restricted to the permissions allowed by the user’s role. A token cannot exceed the permissions of the user it belongs to.
When you create a token, you can set custom permissions to restrict the token’s access below your full role permissions. This lets you issue narrowly scoped tokens for specific tasks, such as a token that can only register agents or a token limited to read-only access.
Token states
Tokens exist in one of two states:
- Active – The token can be used for authentication.
- Revoked – The token is permanently disabled but the record is retained for auditing purposes.
Revoking a token is irreversible. Any agent or client using a revoked token immediately loses access.
Token visibility
Your role determines which tokens you can view and manage:
| Role | Token visibility |
|---|---|
| Owner | All tokens across all users |
| Administrator | All tokens across all users |
| Manager | Only their own tokens |
| Viewer | Cannot manage tokens |
Owner and Administrator users can revoke any token in the organization, including tokens belonging to other users.
Create an API token
Create a new API token for authenticating with the Telegraf Controller API.
Use API tokens
Use API tokens to authenticate Telegraf agents, heartbeat requests, and external API clients with Telegraf Controller.
Reassign a token
Reassign an API token from one user to another in Telegraf Controller.
Revoke a token
Revoke an API token to immediately prevent its use while keeping the token record for auditing.
Delete a token
Permanently delete an API token from Telegraf Controller.
Use pre-shared tokens
Supply your own token value when creating an API token so the same credential authenticates with multiple Telegraf Controller instances.
Bootstrap an owner token
Provision an all-access API token at startup with the OWNER_TOKEN environment variable or the –owner-token command flag.
Was this page helpful?
Thank you for your feedback!
Support and feedback
Thank you for being part of our community! We welcome and encourage your feedback and bug reports for Telegraf Controller and this documentation. To find support, use the following resources:
Customers with an annual or support contract can contact InfluxData Support.