Creating tokens
Tokens are generated automatically by the system and let you establish secure integrations with external services. For each token you can set:- Description — to clearly record its intended use.
- Expiration date — a validity period aligned with your security policy.
- Rate limiting — both a per-minute request limit (Rate Limit per minute) and a total usage quota (Total Request Limit), on a per-token basis.
Multiple tokens per endpoint
Each endpoint supports multiple independent tokens. You can define separate tokens for different integrations, applications, or environments — such as dev, test, and prod — and manage each token’s usage, revocation, and renewal independently. This matters for safe rotation:
Token management is the final authentication step before a request reaches the endpoint defined under Policy Settings. For programmatic use, tokens are passed as described in the Guard Gateway API reference.
Related
Guard Gateway API
How tokens authenticate API requests.
Proxies & Endpoints
The endpoints tokens grant access to.
Policies & Multi-Policy
The policy set applied behind the token.
Platform Overview
Identity and access across the platform.