Managing System Tokens

System tokens may be modified depending on the settings within the Security Policies. If the Update permissions setting is enabled, an existing repository token can be modified to update the permissions granted. In addition, all tokens can be renewed or deleted.

To view the details for an existing token, select the token from the list in the System API Tokens interface. This will show a summary of the organization API token, expiry, permissions, and IP filter information:

  • Expiry information is shown at the top of the summary in both the duration and an explicit date and time when the token will expire. Expiry information cannot be changed.

  • Permission information is shown with each permission and a corresponding green tick (enabled) and red cross (denied). Permission information cannot be changed unless the Update permissions option is enabled within the System token security policy.

If editing the permissions is enabled, click the Update permissions button at the bottom of the dialog.

If the permissions can be updated; click Update permissions to save the updated permissions.

  • To recreate the API token string, click the Reset secret button. This will regenerate the token string so that it can be copied. Resetting the token in this way immediately invalidates the previous token string. The new string will need to be used.

To delete the API token, click the Delete token button. You will be asked to confirm the action. Once deleted, the API token is no longer valid and all API operations with the deleted token will fail.