Manage management tokens
Management tokens grant permission to perform administrative actions such as managing users, databases, and database tokens in your InfluxDB Cloud Dedicated cluster.
Management tokens do not grant permissions to write or query time series data in your InfluxDB Cloud Dedicated cluster.
To grant write or query permissions, use management tokens to create database tokens.
By default, management tokens are short-lived tokens issued by your identity
provider for a specific client session (for example, influxctl
).
However, for automation purposes, you can manually create management tokens that authenticate directly with your InfluxDB Cluster and do not require human interaction with your identity provider. Manually created management tokens provide full access to all account resources and aren’t affected by user groups.
For automation use cases only
The tools outlined below are meant for automation use cases and shouldn’t be used to circumvent your identity provider or user group permissions. Take great care when manually creating and using management tokens.
InfluxDB Cloud Dedicated requires at least one Admin user associated with your cluster and authorized through your OAuth2 identity provider to manually create a management token.
Create a management token
Use the influxctl management create
command to manually create a management token.
influxctl management create \
--expires-at $(date -v+1d -Iseconds) \
--description "Example token description"
List management tokens
Use the influxctl management list
command to list manually-created management tokens.
influxctl management list --format json
Revoke a management token
Use the influxctl management revoke
command to revoke a management token and remove all access associated with the token. Provide the ID of the management token you want to revoke.
influxctl management revoke <TOKEN_ID>
Use a management token
Use management tokens to automate authorization for the
influxctl
CLI:
- Create a management token and securely store the output token value. You’ll use it in the next step.
- On the machine where the
influxctl
CLI is to be automated, update yourinfluxctl
connection profile by assigning themgmt_token
setting to the token string from the preceding step.
[[profile]]
name = "default"
product = "dedicated"
account_id = "ACCOUNT_ID"
cluster_id = "CLUSTER_ID"
mgmt_token = "MANAGEMENT_TOKEN"
Replace the following:
ACCOUNT_ID
: InfluxDB Cloud Dedicated account IDCLUSTER_ID
: InfluxDB Cloud Dedicated cluster IDMANAGEMENT_TOKEN
: Management token string
Was this page helpful?
Thank you for your feedback!
Support and feedback
Thank you for being part of our community! We welcome and encourage your feedback and bug reports for InfluxDB and this documentation. To find support, use the following resources:
Customers with an annual or support contract can contact InfluxData Support.