Skip to content
FluxtailDocs

Access tokens

Access tokens belong to one account and have explicit scopes. Treat the token value as a secret.

Choose the Fluxtail account where the token will be used. For ingest, create the shared receiver first so the token can be bound to it. For read access, decide whether the client needs logs, analytics, or both.

Scope Use
ingest:write Send to one bound shared receiver.
logs:read Read retained logs through the Stream API.
analytics:read Read histograms and facets.

The product also offers an Agent read-only preset for logs:read and analytics:read.

An ingest token must be bound to the same active shared receiver used by the sender. The binding cannot be changed later; create a new token when the receiver changes.

Dedicated receivers use source IPv4 or CIDR rules instead of access tokens.

Open Access tokens, choose Create token, select only the required scopes, and bind ingest:write to the intended receiver. Copy the value when it is shown and move it directly into your secret store or an untracked environment variable.

  • Put tokens in environment variables or your secret manager.
  • Do not place token values in tracked configuration files, screenshots, or support messages.
  • Grant only the scopes needed by the sender or reader.
  • Delete a token that may have been exposed, then update the sender.

Customer Stream requests need both headers:

Authorization: Bearer YOUR_TOKEN
X-Active-Account: YOUR_ACCOUNT_UUID

The account must match the token’s verified account.

For a receiver-bound ingest token, send one known event with the matching sender guide and confirm it in Live Tail. For a read token, make one Stream API request for the intended account and confirm that it returns data without an authentication or scope error.

  • 401 means the token is missing, invalid, or no longer active.
  • 403 means the token lacks the required scope, the account does not match, or an ingest token is bound to another receiver.
  • If a copied token may have been exposed, delete it and create a replacement instead of reusing it.

Configure the matching receiver or follow the Stream API authentication reference. Review stored tokens regularly and remove those that no longer have an owner or active client.