Manage management tokens
Management tokens grant permission to perform administrative actions such as managing users, databases, and database tokens in your InfluxDB cluster.
Management tokens do not grant permissions to write or query time series data in your InfluxDB cluster.
To grant write or query permissions, use management tokens to create database tokens.
By default, management tokens are short-lived tokens issued by an OAuth provider that grant a specific user administrative access to your InfluxDB cluster. However, for automation purposes, you can manually create management tokens that authenticate directly with your InfluxDB Cluster and do not require human interaction with your OAuth provider.
For automation use cases only
The tools outlined below are meant for automation use cases and should not be used to circumvent your OAuth provider. Take great care when manually creating and using management tokens.
InfluxDB Clustered requires at least one user associated with your cluster and authorized through OAuth to manually create a management token.
Create a management token
Use the influxctl management create
command to manually create a management token.
influxctl management create \
--expires-at $(date -v+1d -Iseconds) \
--description "Example token description"
List management tokens
Use the influxctl management list
command to list manually-created management tokens.
influxctl management list --format json
Revoke a management token
Use the influxctl management revoke
command to revoke a management token and remove all access associated with the token. Provide the ID of the management token you want to revoke.
influxctl management revoke <TOKEN_ID>
Use a management token
Use management tokens to automate authorization for the
influxctl
CLI:
- Create a management token and securely store the output token value. You’ll use it in the next step.
- On the machine where the
influxctl
CLI is to be automated, update yourinfluxctl
connection profile by assigning themgmt_token
setting to the token string from the preceding step.
[[profile]]
name = "default"
product = "clustered"
host = "cluster-host.com"
port = "INFLUXDB_PORT"
mgmt_token = "MANAGEMENT_TOKEN"
Replace the following:
INFLUXDB_PORT
: InfluxDB Clustered InfluxDB cluster portMANAGEMENT_TOKEN
: Management token string
Was this page helpful?
Thank you for your feedback!
Support and feedback
Thank you for being part of our community! We welcome and encourage your feedback and bug reports for InfluxDB Clustered and this documentation. To find support, use the following resources:
Customers with an annual or support contract can contact InfluxData Support.