Documentation

Regenerate an admin token

Use the influxdb3 CLI or the HTTP API to regenerate the operator (_admin) token for your InfluxDB 3 Core instance. Regenerate a token to rotate it as part of your security practices or if you suspect the token has been compromised.

Regenerating the operator token deactivates the previous token, stores the SHA512 hash and metadata of the new token, and returns the new token string.

Prerequisite

To regenerate an operator token, you need the current token string.

Use the CLI or HTTP API to regenerate the operator token

Regenerating the operator token

Regenerating the operator token invalidates the previous token. Make sure to update any applications or scripts that use the operator token.

To regenerate the operator token, use the influxdb3 serve create token command (CLI) or the /api/v3/configure/token/admin/regenerate endpoint (HTTP API):

Use the --regenerate flag with the influxdb3 create token --admin subcommand–for example:

influxdb3 create token --admin \
  --regenerate
  
OPERATOR_TOKEN
  • Copy
  • Fill window

In your command, replace OPERATOR_TOKEN with the current operator (_admin) token string.

The output contains the new token string and InfluxDB deactivates the previous token string.

Use the following HTTP API endpoint:

In your request, send an Authorization header with your current operator token string –for example:

curl -X POST "http://localhost:8181/api/v3/configure/token/admin/regenerate" \
  --header "Authorization: Bearer 
OPERATOR_TOKEN
"
\
--header "Accept: application/json"
  • Copy
  • Fill window

In your command, replace OPERATOR_TOKEN with the current token string.

The response body contains the new operator token string in plain text, and InfluxDB deactivates the previous token string.

To use the token as the default for later commands, and to persist the token across sessions, assign the token string to the INFLUXDB3_AUTH_TOKEN environment variable.

Lost admin token recovery

If you’ve lost your admin token and cannot regenerate it using the standard method, you can use the admin token recovery server:

  1. Start InfluxDB 3 Core with the --admin-token-recovery-http-bind option:

    influxdb3 serve --admin-token-recovery-http-bind
    • Copy
    • Fill window
  2. In a separate terminal, regenerate the admin token using the recovery endpoint:

    influxdb3 create token --admin --regenerate --host http://127.0.0.1:8182
    • Copy
    • Fill window
  3. The recovery server automatically shuts down after successful token regeneration.

The recovery server provides unauthenticated access to regenerate admin tokens. Only use this option when necessary and ensure the recovery endpoint (by default 127.0.0.1:8182) is only accessible from trusted networks.

Important considerations

  • Regenerating the operator token invalidates the previous token.
  • If you lose the operator token, use the recovery server method described above.
  • --regenerate only works for the operator token. You can’t use the --regenerate flag with the influxdb3 create token --admin command to regenerate a named admin token.
  • Ensure that you update any applications or scripts that use the operator token with the new token string.
  • Always store your operator token securely and consider implementing proper secret management practices.

Was this page helpful?

Thank you for your feedback!


The future of Flux

Flux is going into maintenance mode. You can continue using it as you currently are without any changes to your code.

Read more

New in InfluxDB 3.3

Key enhancements in InfluxDB 3.3 and the InfluxDB 3 Explorer 1.1.

See the Blog Post

InfluxDB 3.3 is now available for both Core and Enterprise, which introduces new managed plugins for the Processing Engine. This makes it easier to address common time series tasks with just a plugin. InfluxDB 3 Explorer 1.1 is also available, which includes InfluxDB plugin management and other new features.

For more information, check out: