Operational guide to generate, rotate, and revoke admin tokens while minimizing exposure risk.

Generate

Create new token (1 year)

Rotate

Invalidate & replace

Revoke

Immediate invalidation

Audit

Track usage & age

Least Privilege

Limit who can issue

Compliance

Meet rotation policies

Token Basics

AspectValue
Default Expiry1 year (newly generated)
VisibilityShown once at creation dialog
ScopeConsole administrative API operations
Not Available ForSuper Admin accounts
Copy token immediately; it cannot be retrieved later—only regenerated.

Generate Token

1

Navigate

Settings → Admin Users.
2

Options

Click ellipses … next to your admin user.
3

Generate

Select Generate new token.
4

Copy

Securely store in secrets manager.
5

Distribute

Limit distribution to required automation only.

Rotation Strategy

Revoke Token

Admin revokes own token via same menu; session invalidated, re-login required.
Errors when revoking: non-admin attempts or unknown username.

Metrics

MetricDescriptionThreshold
Active TokensCount of valid admin tokensUnexpected growth → audit issuance
Avg Token Age (days)Mean age since creation> 300 → schedule rotations
Orphan TokensTokens with no recent usage (≥30d)>0 → revoke
Compromise IncidentsConfirmed leaksAny >0 → tighten issuance policy

Troubleshooting

IssueLikely CauseFix
Cannot generateSuper Admin accountUse general admin account
Token lostNot stored at creationGenerate new token; revoke old if still active
Script failing after rotationNot updated credentialUpdate secret store & redeploy
Revocation errorUsername mismatchVerify exact admin username