Files

33 lines
36 KiB
HTML
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-2.7 plugin-docs plugin-id-default docs-doc-id-reference-guides/about-the-api/api-tokens" data-has-hydrated="false">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.4.3">
<title data-rh="true">API Tokens | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="2.7"><meta data-rh="true" name="docusaurus_tag" content="docs-default-2.7"><meta data-rh="true" name="docsearch:version" content="2.7"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-2.7"><meta data-rh="true" property="og:title" content="API Tokens | Rancher"><meta data-rh="true" name="description" content="By default, some cluster-level API tokens are generated with infinite time-to-live (ttl=0). In other words, API tokens with ttl=0 never expire unless you invalidate them. Tokens are not invalidated by changing a password."><meta data-rh="true" property="og:description" content="By default, some cluster-level API tokens are generated with infinite time-to-live (ttl=0). In other words, API tokens with ttl=0 never expire unless you invalidate them. Tokens are not invalidated by changing a password."><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/v2.7/reference-guides/about-the-api/api-tokens" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/reference-guides/about-the-api/api-tokens"><link rel="preconnect" href="https://www.googletagmanager.com">
<script>window.dataLayer=window.dataLayer||[]</script>
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.dea80607.css">
<link rel="preload" href="/assets/js/runtime~main.d98f8a34.js" as="script">
<link rel="preload" href="/assets/js/main.e9ebdfba.js" as="script">
</head>
<body class="navigation-with-keyboard">
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/v2.7">v2.7</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/">Latest</a></li><li><a class="dropdown__link" href="/v2.9">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/v2.8">v2.8</a></li><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/v2.7/reference-guides/about-the-api/api-tokens">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/reference-guides/about-the-api/api-tokens">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/reference-guides/about-the-api/api-tokens">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/reference-guides/about-the-api/api-tokens">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/v2.7/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/v2.7/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/v2.7">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/how-to-guides/new-user-guides/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/v2.7/reference-guides/best-practices">Reference Guides</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/best-practices">Best Practice Guides</a><button aria-label="Toggle the collapsible sidebar category &#x27;Best Practice Guides&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/rancher-manager-architecture">Rancher Architecture</a><button aria-label="Toggle the collapsible sidebar category &#x27;Rancher Architecture&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/cluster-configuration">Cluster Configuration</a><button aria-label="Toggle the collapsible sidebar category &#x27;Cluster Configuration&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/single-node-rancher-in-docker">Single-Node Rancher in Docker</a><button aria-label="Toggle the collapsible sidebar category &#x27;Single-Node Rancher in Docker&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/backup-restore-configuration">Backup &amp; Restore Configuration</a><button aria-label="Toggle the collapsible sidebar category &#x27;Backup &amp; Restore Configuration&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/kubernetes-concepts">Kubernetes Concepts</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/monitoring-v2-configuration">Monitoring Configuration Reference</a><button aria-label="Toggle the collapsible sidebar category &#x27;Monitoring Configuration Reference&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/prometheus-federator">Prometheus Federator</a><button aria-label="Toggle the collapsible sidebar category &#x27;Prometheus Federator&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/user-settings">User Settings</a><button aria-label="Toggle the collapsible sidebar category &#x27;User Settings&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/cli-with-rancher">CLI with Rancher</a><button aria-label="Toggle the collapsible sidebar category &#x27;CLI with Rancher&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" tabindex="0" href="/v2.7/reference-guides/about-the-api">About the API</a><button aria-label="Toggle the collapsible sidebar category &#x27;About the API&#x27;" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/v2.7/reference-guides/about-the-api/api-tokens">API Tokens</a></li></ul></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-cluster-tools">Cluster Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-project-tools">Project Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/system-tools">System Tools</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rke1-template-example-yaml">RKE1 Example YAML</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-webhook">Rancher Webhook</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/rancher-security">Rancher Security Guides</a><button aria-label="Toggle the collapsible sidebar category &#x27;Rancher Security Guides&#x27;" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/integrations-in-rancher/cloud-marketplace">Integrations in Rancher</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/v2.7/contribute-to-rancher">Contributing to Rancher</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Reference Guides</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/v2.7/reference-guides/about-the-api"><span itemprop="name">About the API</span></a><meta itemprop="position" content="2"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">API Tokens</span><meta itemprop="position" content="3"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: v2.7</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>API Tokens</h1></header><p>By default, some cluster-level API tokens are generated with infinite time-to-live (<code>ttl=0</code>). In other words, API tokens with <code>ttl=0</code> never expire unless you invalidate them. Tokens are not invalidated by changing a password.</p><p>You can deactivate API tokens by deleting them or by deactivating the user account.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="deleting-tokens">Deleting Tokens<a href="#deleting-tokens" class="hash-link" aria-label="Direct link to Deleting Tokens" title="Direct link to Deleting Tokens">​</a></h2><p>To delete a token:</p><ol><li><p>Go to the list of all tokens in the Rancher API view at <code>https://&lt;Rancher-Server-IP&gt;/v3/tokens</code>.</p></li><li><p>Access the token you want to delete by its ID. For example, <code>https://&lt;Rancher-Server-IP&gt;/v3/tokens/kubectl-shell-user-vqkqt</code></p></li><li><p>Click <strong>Delete</strong>.</p></li></ol><p>The following is a complete list of tokens generated with <code>ttl=0</code>:</p><table><thead><tr><th>Token</th><th>Description</th></tr></thead><tbody><tr><td><code>kubeconfig-*</code></td><td>Kubeconfig token</td></tr><tr><td><code>kubectl-shell-*</code></td><td>Access to <code>kubectl</code> shell in the browser</td></tr><tr><td><code>agent-*</code></td><td>Token for agent deployment</td></tr><tr><td><code>compose-token-*</code></td><td>Token for compose</td></tr><tr><td><code>helm-token-*</code></td><td>Token for Helm chart deployment</td></tr><tr><td><code>telemetry-*</code></td><td>Telemetry token</td></tr><tr><td><code>drain-node-*</code></td><td>Token for drain (Rancher uses <code>kubectl</code> for drain because there is no native Kubernetes API)</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="setting-ttl-on-kubeconfig-tokens">Setting TTL on Kubeconfig Tokens<a href="#setting-ttl-on-kubeconfig-tokens" class="hash-link" aria-label="Direct link to Setting TTL on Kubeconfig Tokens" title="Direct link to Setting TTL on Kubeconfig Tokens">​</a></h3><p>Admins can set a global time-to-live (TTL) on Kubeconfig tokens. Changing the default kubeconfig TTL can be done by navigating to global settings and setting <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> to the desired duration in minutes. The default value of <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> is <code>0</code>, which means that tokens never expire.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>This setting is used by all kubeconfig tokens except those created by the CLI to <a href="#disable-tokens-in-generated-kubeconfigs">generate kubeconfig tokens</a>.</p></div></div><h2 class="anchor anchorWithStickyNavbar_LWe7" id="disable-tokens-in-generated-kubeconfigs">Disable Tokens in Generated Kubeconfigs<a href="#disable-tokens-in-generated-kubeconfigs" class="hash-link" aria-label="Direct link to Disable Tokens in Generated Kubeconfigs" title="Direct link to Disable Tokens in Generated Kubeconfigs">​</a></h2><ol><li><p>Set the <code>kubeconfig-generate-token</code> setting to <code>false</code>. This setting instructs Rancher to no longer automatically generate a token when a user clicks on download a kubeconfig file. When this setting is deactivated, a generated kubeconfig references the <a href="/v2.7/reference-guides/cli-with-rancher/kubectl-utility#authentication-with-kubectl-and-kubeconfig-tokens-with-ttl">Rancher CLI</a> to retrieve a short-lived token for the cluster. When this kubeconfig is used in a client, such as <code>kubectl</code>, the Rancher CLI needs to be installed to complete the log in request.</p></li><li><p>Set the <code>kubeconfig-token-ttl-minutes</code> setting to the desired duration in minutes. By default, <code>kubeconfig-token-ttl-minutes</code> is <code>960</code> (16 hours).</p></li></ol><h2 class="anchor anchorWithStickyNavbar_LWe7" id="token-hashing">Token Hashing<a href="#token-hashing" class="hash-link" aria-label="Direct link to Token Hashing" title="Direct link to Token Hashing">​</a></h2><p>Users can enable token hashing, where tokens undergo a one-way hash using the SHA256 algorithm. This is a non-reversible process: once enabled, this feature cannot be disabled. It is advisable to take backups prior to enabling and/or evaluating in a test environment first.</p><p>To enable token hashing, refer to <a href="/v2.7/how-to-guides/advanced-user-guides/enable-experimental-features">this section</a>.</p><p>This feature affects all tokens which include, but are not limited to, the following:</p><ul><li>Kubeconfig tokens</li><li>Bearer tokens API keys/calls</li><li>Tokens used by internal operations</li></ul><h2 class="anchor anchorWithStickyNavbar_LWe7" id="token-settings">Token Settings<a href="#token-settings" class="hash-link" aria-label="Direct link to Token Settings" title="Direct link to Token Settings">​</a></h2><p>These global settings affect Rancher token behavior.</p><table><thead><tr><th>Setting</th><th>Description</th></tr></thead><tbody><tr><td><a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a></td><td>TTL in minutes on a user auth session token.</td></tr><tr><td><a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a></td><td>Default TTL applied to all kubeconfig tokens except those <a href="#disable-tokens-in-generated-kubeconfigs">generated by Rancher CLI</a>. <strong>Introduced in version 2.6.6.</strong></td></tr><tr><td><a href="#kubeconfig-token-ttl-minutes"><code>kubeconfig-token-ttl-minutes</code></a></td><td>TTL used for tokens generated via the CLI. <strong>Deprecated since version 2.6.6, and removed in 2.8.0.</strong> Rancher v2.8 and later instead use <code>kubeconfig-default-token-ttl-minutes</code> for all kubeconfig tokens.</td></tr><tr><td><a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a></td><td>Max TTL for all tokens except those controlled by <a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a>. May override <code>kubeconfig-default-token-ttl-minutes</code>.</td></tr><tr><td><a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a></td><td>If true, automatically generate tokens when a user downloads a kubeconfig.</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="auth-user-session-ttl-minutes">auth-user-session-ttl-minutes<a href="#auth-user-session-ttl-minutes" class="hash-link" aria-label="Direct link to auth-user-session-ttl-minutes" title="Direct link to auth-user-session-ttl-minutes">​</a></h3><p>Time to live (TTL) duration in minutes, used to determine when a user auth session token expires. When expired, the user must log in and obtain a new token. This setting is not affected by <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>. Session tokens are created when a user logs into Rancher.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-default-token-ttl-minutes">kubeconfig-default-token-ttl-minutes<a href="#kubeconfig-default-token-ttl-minutes" class="hash-link" aria-label="Direct link to kubeconfig-default-token-ttl-minutes" title="Direct link to kubeconfig-default-token-ttl-minutes">​</a></h3><p>Time to live (TTL) duration in minutes, used to determine when a kubeconfig token expires. When the token is expired, the API rejects the token. This setting can&#x27;t be larger than <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>. This setting applies to tokens generated in a requested kubeconfig file, except for tokens <a href="#disable-tokens-in-generated-kubeconfigs">generated by Rancher CLI</a>. The default value is <code>0</code>, which means that tokens never expire.
<strong>Introduced in version 2.6.6</strong>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-token-ttl-minutes">kubeconfig-token-ttl-minutes<a href="#kubeconfig-token-ttl-minutes" class="hash-link" aria-label="Direct link to kubeconfig-token-ttl-minutes" title="Direct link to kubeconfig-token-ttl-minutes">​</a></h3><p>Time to live (TTL) duration in minutes used to determine when a kubeconfig token that was generated by the CLI expires. Tokens are generated by the CLI when <a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a> is false. When the token is expired, the API rejects the token. This setting can&#x27;t be larger than <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>.
<strong>Deprecated since Rancher v2.6.6.</strong></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="auth-token-max-ttl-minutes">auth-token-max-ttl-minutes<a href="#auth-token-max-ttl-minutes" class="hash-link" aria-label="Direct link to auth-token-max-ttl-minutes" title="Direct link to auth-token-max-ttl-minutes">​</a></h3><p>Maximum Time to Live (TTL) in minutes allowed for auth tokens. If a user attempts to create a token with a TTL greater than <code>auth-token-max-ttl-minutes</code>, Rancher sets the token TTL to the value of <code>auth-token-max-ttl-minutes</code>. Applies to all kubeconfig tokens and API tokens. The default value is <code>0</code>, which means that tokens never expire.
<strong>Rancher v2.6.5 and earlier: Applies only to tokens created for authenticating API requests.</strong></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-generate-token">kubeconfig-generate-token<a href="#kubeconfig-generate-token" class="hash-link" aria-label="Direct link to kubeconfig-generate-token" title="Direct link to kubeconfig-generate-token">​</a></h3><p>When true, kubeconfigs requested through the UI contain a valid token. When false, kubeconfigs contain a command that uses the Rancher CLI to prompt the user to log in. <a href="/v2.7/reference-guides/cli-with-rancher/kubectl-utility#authentication-with-kubectl-and-kubeconfig-tokens-with-ttl">The CLI then retrieves and caches a token for the user</a>.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/reference-guides/about-the-api/api-tokens.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2024-03-25T22:05:17.000Z">Mar 25, 2024</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/v2.7/reference-guides/about-the-api"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">API</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/v2.7/reference-guides/rancher-cluster-tools"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Cluster Tools for Logging, Monitoring, and Visibility</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#deleting-tokens" class="table-of-contents__link toc-highlight">Deleting Tokens</a><ul><li><a href="#setting-ttl-on-kubeconfig-tokens" class="table-of-contents__link toc-highlight">Setting TTL on Kubeconfig Tokens</a></li></ul></li><li><a href="#disable-tokens-in-generated-kubeconfigs" class="table-of-contents__link toc-highlight">Disable Tokens in Generated Kubeconfigs</a></li><li><a href="#token-hashing" class="table-of-contents__link toc-highlight">Token Hashing</a></li><li><a href="#token-settings" class="table-of-contents__link toc-highlight">Token Settings</a><ul><li><a href="#auth-user-session-ttl-minutes" class="table-of-contents__link toc-highlight">auth-user-session-ttl-minutes</a></li><li><a href="#kubeconfig-default-token-ttl-minutes" class="table-of-contents__link toc-highlight">kubeconfig-default-token-ttl-minutes</a></li><li><a href="#kubeconfig-token-ttl-minutes" class="table-of-contents__link toc-highlight">kubeconfig-token-ttl-minutes</a></li><li><a href="#auth-token-max-ttl-minutes" class="table-of-contents__link toc-highlight">auth-token-max-ttl-minutes</a></li><li><a href="#kubeconfig-generate-token" class="table-of-contents__link toc-highlight">kubeconfig-generate-token</a></li></ul></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/assets/js/runtime~main.d98f8a34.js"></script>
<script src="/assets/js/main.e9ebdfba.js"></script>
</body>
</html>