> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Token Management for Endpoint Access

> Issue, scope, and rotate the access tokens that authenticate integrations to your BeyondGuard endpoints — with per-token rate limits and multiple tokens per endpoint.

**Token Management** is the authentication layer for every integration and API access to the AI Proxy. From the **Token Configuration** screen you create tokens for specific purposes, describe them, and configure their access limits in detail.

## Creating tokens

Tokens are generated automatically by the system and let you establish secure integrations with external services. For each token you can set:

* **Description** — to clearly record its intended use.
* **Expiration date** — a validity period aligned with your security policy.
* **Rate limiting** — both a per-minute request limit (**Rate Limit per minute**) and a total usage quota (**Total Request Limit**), on a per-token basis.

These limits reduce the risk of misuse, excessive queries, and unauthorized access, making token-based traffic controllable at enterprise scale.

## Multiple tokens per endpoint

Each endpoint supports **multiple independent tokens**. You can define separate tokens for different integrations, applications, or environments — such as **dev, test, and prod** — and manage each token's usage, revocation, and renewal independently.

This matters for safe rotation:

| Benefit | What it means |
| - | - |
| **Safer token rotation** | Rotate or revoke a single token without interrupting every integration on the endpoint. |
| **Reduced outage risk** | A compromised or expired token can be disabled while other clients keep operating. |
| **Clearer access separation** | Keep environments and integrations isolated with dedicated tokens. |
| **Stronger accountability** | Track which client accessed the system with which token, and when. |

<Warning>
  Previously, a single token per endpoint meant any rotation (leakage, policy, or integration change) could disrupt every client at once. Multiple-token support removes that single point of failure — prefer a dedicated token per integration and environment.
</Warning>

Token management is the final authentication step before a request reaches the endpoint defined under [Policy Settings](/platform/policies). For programmatic use, tokens are passed as described in the [Guard Gateway API](/api-reference/guard-gateway) reference.

## Related

<CardGroup cols={2}>
  <Card title="Guard Gateway API" icon="code" href="/api-reference/guard-gateway">
    How tokens authenticate API requests.
  </Card>

  <Card title="Proxies & Endpoints" icon="arrow-right-arrow-left" href="/platform/proxies">
    The endpoints tokens grant access to.
  </Card>

  <Card title="Policies & Multi-Policy" icon="sliders" href="/platform/policies">
    The policy set applied behind the token.
  </Card>

  <Card title="Platform Overview" icon="grid-2" href="/platform/overview">
    Identity and access across the platform.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.