Skip to content

Enrollment Tokens

Enrollment Tokens authorize enrollment for endpoints and service clients.

Open Administration > Enrollment Tokens.

Token Scope

When creating a token, choose the intended enrollment scope and related target options.

Use endpoint enrollment tokens for endpoint agents. Use service-client enrollment tokens for service clients such as Edge-adjacent services, Cache Nodes, Webhooks, SNMP, Telematik, Package Discovery, and Net where the service setup requires one.

Service-client enrollment tokens are used for enrollment and certificate renewal. After enrollment succeeds, the service client authenticates with its local certificate state.

Creating Tokens

When issuing a token, configure:

  • label
  • tenant
  • token purpose
  • service-client type, Edge service, and service client when the purpose is Service client
  • usage policy
  • approval policy
  • optional expiration date

Usage policies are:

  • Single endpoint: consumed by the first successful enrollment.
  • Limited uses: valid for a fixed number of successful enrollments.
  • Unlimited uses: reusable until it expires, is exhausted, or is invalidated.

Approval policies are:

  • Manual approval: newly enrolled endpoints wait for operator approval.
  • Automatic approval: newly enrolled endpoints become approved after successful enrollment.

The plaintext token is shown only once after creation. Capture it before closing the panel.

Token List

The token table shows:

  • label and created time
  • last used time, when available
  • tenant
  • remaining uses and successful enrollment count
  • approval policy
  • expiration or invalidation time
  • status

Use search to find tokens by label and the status filter to focus on active, expired, exhausted, or invalidated tokens.

Active tokens can be invalidated from the table. Active tokens with remaining uses can also have their approval policy changed.

Handling Tokens

Enrollment tokens are sensitive. Treat them like temporary credentials:

  • create them only for the intended setup task
  • copy them only into the enrollment prompt or setup command
  • revoke or let them expire when they are not needed

After enrollment succeeds, the enrolled endpoint or service client authenticates with its certificate.

Service-Client Renewal

Use a service-client enrollment token when a service client needs a fresh certificate. This is the same operator workflow used for the first enrollment:

  1. Create a token with purpose Service client.
  2. Select the service-client type, Edge service, and exact service client.
  3. Copy the plaintext token shown after creation.
  4. Run the service client's enrollment command with that token.
  5. Restart the service container and confirm that the service-client detail page shows the updated certificate expiration.

If a service-client certificate is expired or revoked, the service client cannot connect until this enrollment workflow succeeds.