Operational guide to generate, rotate, and revoke admin tokens while minimizing exposure risk.
Generate
Create new token (1 year)
Rotate
Invalidate & replace
Revoke
Immediate invalidation
Audit
Track usage & age
Least Privilege
Limit who can issue
Compliance
Meet rotation policies
Token Basics
Generate Token
1
Navigate
Settings → Admin Users.
2
Options
Click ellipses … next to your admin user.
3
Generate
Select Generate new token.
4
Copy
Securely store in secrets manager.
5
Distribute
Limit distribution to required automation only.
Rotation Strategy
Planned Rotation
Planned Rotation
Generate replacement token → update dependent services → revoke old (grace window ≤24h).
Unplanned Rotation
Unplanned Rotation
Suspected leak → immediate revoke → generate new → notify stakeholders.
Inventory Tracking
Inventory Tracking
Maintain registry: owner, creation date, last used timestamp.
Automation Use
Automation Use
Prefer service-specific tokens rather than sharing a personal admin’s token.
Revoke Token
- Self-Revoke
- Super Admin Revoke
- Post-Revoke
Admin revokes own token via same menu; session invalidated, re-login required.
Errors when revoking: non-admin attempts or unknown username.
Metrics
Troubleshooting
Related
Security
Secure Mode & mTLS
Admin Access
Permission governance