Skip to main content
Token Management is the authentication layer for every integration and API access to the AI Proxy. From the Token Configuration screen you create tokens for specific purposes, describe them, and configure their access limits in detail.

Creating tokens

Tokens are generated automatically by the system and let you establish secure integrations with external services. For each token you can set:
  • Description — to clearly record its intended use.
  • Expiration date — a validity period aligned with your security policy.
  • Rate limiting — both a per-minute request limit (Rate Limit per minute) and a total usage quota (Total Request Limit), on a per-token basis.
These limits reduce the risk of misuse, excessive queries, and unauthorized access, making token-based traffic controllable at enterprise scale.

Multiple tokens per endpoint

Each endpoint supports multiple independent tokens. You can define separate tokens for different integrations, applications, or environments — such as dev, test, and prod — and manage each token’s usage, revocation, and renewal independently. This matters for safe rotation:
Previously, a single token per endpoint meant any rotation (leakage, policy, or integration change) could disrupt every client at once. Multiple-token support removes that single point of failure — prefer a dedicated token per integration and environment.
Token management is the final authentication step before a request reaches the endpoint defined under Policy Settings. For programmatic use, tokens are passed as described in the Guard Gateway API reference.

Guard Gateway API

How tokens authenticate API requests.

Proxies & Endpoints

The endpoints tokens grant access to.

Policies & Multi-Policy

The policy set applied behind the token.

Platform Overview

Identity and access across the platform.