mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-25 12:38:05 +00:00
33 lines
36 KiB
HTML
33 lines
36 KiB
HTML
<!doctype html>
|
||
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-2.7 plugin-docs plugin-id-default docs-doc-id-reference-guides/about-the-api/api-tokens" data-has-hydrated="false">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="generator" content="Docusaurus v2.4.3">
|
||
<title data-rh="true">API Tokens | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="2.7"><meta data-rh="true" name="docusaurus_tag" content="docs-default-2.7"><meta data-rh="true" name="docsearch:version" content="2.7"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-2.7"><meta data-rh="true" property="og:title" content="API Tokens | Rancher"><meta data-rh="true" name="description" content="By default, some cluster-level API tokens are generated with infinite time-to-live (ttl=0). In other words, API tokens with ttl=0 never expire unless you invalidate them. Tokens are not invalidated by changing a password."><meta data-rh="true" property="og:description" content="By default, some cluster-level API tokens are generated with infinite time-to-live (ttl=0). In other words, API tokens with ttl=0 never expire unless you invalidate them. Tokens are not invalidated by changing a password."><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/v2.7/reference-guides/about-the-api/api-tokens" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/v2.7/reference-guides/about-the-api/api-tokens" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/reference-guides/about-the-api/api-tokens"><link rel="preconnect" href="https://www.googletagmanager.com">
|
||
<script>window.dataLayer=window.dataLayer||[]</script>
|
||
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
|
||
|
||
|
||
|
||
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
|
||
|
||
|
||
|
||
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
|
||
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.dea80607.css">
|
||
<link rel="preload" href="/assets/js/runtime~main.d98f8a34.js" as="script">
|
||
<link rel="preload" href="/assets/js/main.e9ebdfba.js" as="script">
|
||
</head>
|
||
<body class="navigation-with-keyboard">
|
||
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
|
||
|
||
|
||
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
|
||
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/v2.7">v2.7</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/">Latest</a></li><li><a class="dropdown__link" href="/v2.9">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/v2.8">v2.8</a></li><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/v2.7/reference-guides/about-the-api/api-tokens">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/reference-guides/about-the-api/api-tokens">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/reference-guides/about-the-api/api-tokens">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/reference-guides/about-the-api/api-tokens">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/v2.7/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/v2.7/reference-guides/about-the-api/api-tokens" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/v2.7">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/how-to-guides/new-user-guides/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/v2.7/reference-guides/best-practices">Reference Guides</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/best-practices">Best Practice Guides</a><button aria-label="Toggle the collapsible sidebar category 'Best Practice Guides'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/rancher-manager-architecture">Rancher Architecture</a><button aria-label="Toggle the collapsible sidebar category 'Rancher Architecture'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/cluster-configuration">Cluster Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Cluster Configuration'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/single-node-rancher-in-docker">Single-Node Rancher in Docker</a><button aria-label="Toggle the collapsible sidebar category 'Single-Node Rancher in Docker'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/backup-restore-configuration">Backup & Restore Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Backup & Restore Configuration'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/kubernetes-concepts">Kubernetes Concepts</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/monitoring-v2-configuration">Monitoring Configuration Reference</a><button aria-label="Toggle the collapsible sidebar category 'Monitoring Configuration Reference'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/prometheus-federator">Prometheus Federator</a><button aria-label="Toggle the collapsible sidebar category 'Prometheus Federator'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/user-settings">User Settings</a><button aria-label="Toggle the collapsible sidebar category 'User Settings'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/cli-with-rancher">CLI with Rancher</a><button aria-label="Toggle the collapsible sidebar category 'CLI with Rancher'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" tabindex="0" href="/v2.7/reference-guides/about-the-api">About the API</a><button aria-label="Toggle the collapsible sidebar category 'About the API'" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/v2.7/reference-guides/about-the-api/api-tokens">API Tokens</a></li></ul></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-cluster-tools">Cluster Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-project-tools">Project Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/system-tools">System Tools</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rke1-template-example-yaml">RKE1 Example YAML</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/v2.7/reference-guides/rancher-webhook">Rancher Webhook</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/v2.7/reference-guides/rancher-security">Rancher Security Guides</a><button aria-label="Toggle the collapsible sidebar category 'Rancher Security Guides'" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/integrations-in-rancher/cloud-marketplace">Integrations in Rancher</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/v2.7/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/v2.7/contribute-to-rancher">Contributing to Rancher</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Reference Guides</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/v2.7/reference-guides/about-the-api"><span itemprop="name">About the API</span></a><meta itemprop="position" content="2"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">API Tokens</span><meta itemprop="position" content="3"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: v2.7</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>API Tokens</h1></header><p>By default, some cluster-level API tokens are generated with infinite time-to-live (<code>ttl=0</code>). In other words, API tokens with <code>ttl=0</code> never expire unless you invalidate them. Tokens are not invalidated by changing a password.</p><p>You can deactivate API tokens by deleting them or by deactivating the user account.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="deleting-tokens">Deleting Tokens<a href="#deleting-tokens" class="hash-link" aria-label="Direct link to Deleting Tokens" title="Direct link to Deleting Tokens"></a></h2><p>To delete a token:</p><ol><li><p>Go to the list of all tokens in the Rancher API view at <code>https://<Rancher-Server-IP>/v3/tokens</code>.</p></li><li><p>Access the token you want to delete by its ID. For example, <code>https://<Rancher-Server-IP>/v3/tokens/kubectl-shell-user-vqkqt</code></p></li><li><p>Click <strong>Delete</strong>.</p></li></ol><p>The following is a complete list of tokens generated with <code>ttl=0</code>:</p><table><thead><tr><th>Token</th><th>Description</th></tr></thead><tbody><tr><td><code>kubeconfig-*</code></td><td>Kubeconfig token</td></tr><tr><td><code>kubectl-shell-*</code></td><td>Access to <code>kubectl</code> shell in the browser</td></tr><tr><td><code>agent-*</code></td><td>Token for agent deployment</td></tr><tr><td><code>compose-token-*</code></td><td>Token for compose</td></tr><tr><td><code>helm-token-*</code></td><td>Token for Helm chart deployment</td></tr><tr><td><code>telemetry-*</code></td><td>Telemetry token</td></tr><tr><td><code>drain-node-*</code></td><td>Token for drain (Rancher uses <code>kubectl</code> for drain because there is no native Kubernetes API)</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="setting-ttl-on-kubeconfig-tokens">Setting TTL on Kubeconfig Tokens<a href="#setting-ttl-on-kubeconfig-tokens" class="hash-link" aria-label="Direct link to Setting TTL on Kubeconfig Tokens" title="Direct link to Setting TTL on Kubeconfig Tokens"></a></h3><p>Admins can set a global time-to-live (TTL) on Kubeconfig tokens. Changing the default kubeconfig TTL can be done by navigating to global settings and setting <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> to the desired duration in minutes. The default value of <a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a> is <code>0</code>, which means that tokens never expire.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>This setting is used by all kubeconfig tokens except those created by the CLI to <a href="#disable-tokens-in-generated-kubeconfigs">generate kubeconfig tokens</a>.</p></div></div><h2 class="anchor anchorWithStickyNavbar_LWe7" id="disable-tokens-in-generated-kubeconfigs">Disable Tokens in Generated Kubeconfigs<a href="#disable-tokens-in-generated-kubeconfigs" class="hash-link" aria-label="Direct link to Disable Tokens in Generated Kubeconfigs" title="Direct link to Disable Tokens in Generated Kubeconfigs"></a></h2><ol><li><p>Set the <code>kubeconfig-generate-token</code> setting to <code>false</code>. This setting instructs Rancher to no longer automatically generate a token when a user clicks on download a kubeconfig file. When this setting is deactivated, a generated kubeconfig references the <a href="/v2.7/reference-guides/cli-with-rancher/kubectl-utility#authentication-with-kubectl-and-kubeconfig-tokens-with-ttl">Rancher CLI</a> to retrieve a short-lived token for the cluster. When this kubeconfig is used in a client, such as <code>kubectl</code>, the Rancher CLI needs to be installed to complete the log in request.</p></li><li><p>Set the <code>kubeconfig-token-ttl-minutes</code> setting to the desired duration in minutes. By default, <code>kubeconfig-token-ttl-minutes</code> is <code>960</code> (16 hours).</p></li></ol><h2 class="anchor anchorWithStickyNavbar_LWe7" id="token-hashing">Token Hashing<a href="#token-hashing" class="hash-link" aria-label="Direct link to Token Hashing" title="Direct link to Token Hashing"></a></h2><p>Users can enable token hashing, where tokens undergo a one-way hash using the SHA256 algorithm. This is a non-reversible process: once enabled, this feature cannot be disabled. It is advisable to take backups prior to enabling and/or evaluating in a test environment first.</p><p>To enable token hashing, refer to <a href="/v2.7/how-to-guides/advanced-user-guides/enable-experimental-features">this section</a>.</p><p>This feature affects all tokens which include, but are not limited to, the following:</p><ul><li>Kubeconfig tokens</li><li>Bearer tokens API keys/calls</li><li>Tokens used by internal operations</li></ul><h2 class="anchor anchorWithStickyNavbar_LWe7" id="token-settings">Token Settings<a href="#token-settings" class="hash-link" aria-label="Direct link to Token Settings" title="Direct link to Token Settings"></a></h2><p>These global settings affect Rancher token behavior.</p><table><thead><tr><th>Setting</th><th>Description</th></tr></thead><tbody><tr><td><a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a></td><td>TTL in minutes on a user auth session token.</td></tr><tr><td><a href="#kubeconfig-default-token-ttl-minutes"><code>kubeconfig-default-token-ttl-minutes</code></a></td><td>Default TTL applied to all kubeconfig tokens except those <a href="#disable-tokens-in-generated-kubeconfigs">generated by Rancher CLI</a>. <strong>Introduced in version 2.6.6.</strong></td></tr><tr><td><a href="#kubeconfig-token-ttl-minutes"><code>kubeconfig-token-ttl-minutes</code></a></td><td>TTL used for tokens generated via the CLI. <strong>Deprecated since version 2.6.6, and removed in 2.8.0.</strong> Rancher v2.8 and later instead use <code>kubeconfig-default-token-ttl-minutes</code> for all kubeconfig tokens.</td></tr><tr><td><a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a></td><td>Max TTL for all tokens except those controlled by <a href="#auth-user-session-ttl-minutes"><code>auth-user-session-ttl-minutes</code></a>. May override <code>kubeconfig-default-token-ttl-minutes</code>.</td></tr><tr><td><a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a></td><td>If true, automatically generate tokens when a user downloads a kubeconfig.</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="auth-user-session-ttl-minutes">auth-user-session-ttl-minutes<a href="#auth-user-session-ttl-minutes" class="hash-link" aria-label="Direct link to auth-user-session-ttl-minutes" title="Direct link to auth-user-session-ttl-minutes"></a></h3><p>Time to live (TTL) duration in minutes, used to determine when a user auth session token expires. When expired, the user must log in and obtain a new token. This setting is not affected by <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>. Session tokens are created when a user logs into Rancher.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-default-token-ttl-minutes">kubeconfig-default-token-ttl-minutes<a href="#kubeconfig-default-token-ttl-minutes" class="hash-link" aria-label="Direct link to kubeconfig-default-token-ttl-minutes" title="Direct link to kubeconfig-default-token-ttl-minutes"></a></h3><p>Time to live (TTL) duration in minutes, used to determine when a kubeconfig token expires. When the token is expired, the API rejects the token. This setting can't be larger than <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>. This setting applies to tokens generated in a requested kubeconfig file, except for tokens <a href="#disable-tokens-in-generated-kubeconfigs">generated by Rancher CLI</a>. The default value is <code>0</code>, which means that tokens never expire.
|
||
<strong>Introduced in version 2.6.6</strong>.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-token-ttl-minutes">kubeconfig-token-ttl-minutes<a href="#kubeconfig-token-ttl-minutes" class="hash-link" aria-label="Direct link to kubeconfig-token-ttl-minutes" title="Direct link to kubeconfig-token-ttl-minutes"></a></h3><p>Time to live (TTL) duration in minutes used to determine when a kubeconfig token that was generated by the CLI expires. Tokens are generated by the CLI when <a href="#kubeconfig-generate-token"><code>kubeconfig-generate-token</code></a> is false. When the token is expired, the API rejects the token. This setting can't be larger than <a href="#auth-token-max-ttl-minutes"><code>auth-token-max-ttl-minutes</code></a>.
|
||
<strong>Deprecated since Rancher v2.6.6.</strong></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="auth-token-max-ttl-minutes">auth-token-max-ttl-minutes<a href="#auth-token-max-ttl-minutes" class="hash-link" aria-label="Direct link to auth-token-max-ttl-minutes" title="Direct link to auth-token-max-ttl-minutes"></a></h3><p>Maximum Time to Live (TTL) in minutes allowed for auth tokens. If a user attempts to create a token with a TTL greater than <code>auth-token-max-ttl-minutes</code>, Rancher sets the token TTL to the value of <code>auth-token-max-ttl-minutes</code>. Applies to all kubeconfig tokens and API tokens. The default value is <code>0</code>, which means that tokens never expire.
|
||
<strong>Rancher v2.6.5 and earlier: Applies only to tokens created for authenticating API requests.</strong></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="kubeconfig-generate-token">kubeconfig-generate-token<a href="#kubeconfig-generate-token" class="hash-link" aria-label="Direct link to kubeconfig-generate-token" title="Direct link to kubeconfig-generate-token"></a></h3><p>When true, kubeconfigs requested through the UI contain a valid token. When false, kubeconfigs contain a command that uses the Rancher CLI to prompt the user to log in. <a href="/v2.7/reference-guides/cli-with-rancher/kubectl-utility#authentication-with-kubectl-and-kubeconfig-tokens-with-ttl">The CLI then retrieves and caches a token for the user</a>.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.7/reference-guides/about-the-api/api-tokens.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2024-03-25T22:05:17.000Z">Mar 25, 2024</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/v2.7/reference-guides/about-the-api"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">API</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/v2.7/reference-guides/rancher-cluster-tools"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Cluster Tools for Logging, Monitoring, and Visibility</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#deleting-tokens" class="table-of-contents__link toc-highlight">Deleting Tokens</a><ul><li><a href="#setting-ttl-on-kubeconfig-tokens" class="table-of-contents__link toc-highlight">Setting TTL on Kubeconfig Tokens</a></li></ul></li><li><a href="#disable-tokens-in-generated-kubeconfigs" class="table-of-contents__link toc-highlight">Disable Tokens in Generated Kubeconfigs</a></li><li><a href="#token-hashing" class="table-of-contents__link toc-highlight">Token Hashing</a></li><li><a href="#token-settings" class="table-of-contents__link toc-highlight">Token Settings</a><ul><li><a href="#auth-user-session-ttl-minutes" class="table-of-contents__link toc-highlight">auth-user-session-ttl-minutes</a></li><li><a href="#kubeconfig-default-token-ttl-minutes" class="table-of-contents__link toc-highlight">kubeconfig-default-token-ttl-minutes</a></li><li><a href="#kubeconfig-token-ttl-minutes" class="table-of-contents__link toc-highlight">kubeconfig-token-ttl-minutes</a></li><li><a href="#auth-token-max-ttl-minutes" class="table-of-contents__link toc-highlight">auth-token-max-ttl-minutes</a></li><li><a href="#kubeconfig-generate-token" class="table-of-contents__link toc-highlight">kubeconfig-generate-token</a></li></ul></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
|
||
<script src="/assets/js/runtime~main.d98f8a34.js"></script>
|
||
<script src="/assets/js/main.e9ebdfba.js"></script>
|
||
</body>
|
||
</html> |