Access tokens
Access tokens belong to one account and have explicit scopes. Treat the token value as a secret.
Prerequisites
Section titled “Prerequisites”Choose the Fluxtail account where the token will be used. For ingest, create the shared receiver first so the token can be bound to it. For read access, decide whether the client needs logs, analytics, or both.
Common scopes
Section titled “Common scopes”| Scope | Use |
|---|---|
ingest:write |
Send to one bound shared receiver. |
logs:read |
Read retained logs through the Stream API. |
analytics:read |
Read histograms and facets. |
The product also offers an Agent read-only preset for logs:read and analytics:read.
Receiver-bound ingest tokens
Section titled “Receiver-bound ingest tokens”An ingest token must be bound to the same active shared receiver used by the sender. The binding cannot be changed later; create a new token when the receiver changes.
Dedicated receivers use source IPv4 or CIDR rules instead of access tokens.
Create a token
Section titled “Create a token”Open Access tokens, choose Create token, select only the required scopes, and bind ingest:write to the intended receiver. Copy the value when it is shown and move it directly into your secret store or an untracked environment variable.
Store tokens safely
Section titled “Store tokens safely”- Put tokens in environment variables or your secret manager.
- Do not place token values in tracked configuration files, screenshots, or support messages.
- Grant only the scopes needed by the sender or reader.
- Delete a token that may have been exposed, then update the sender.
Stream API authentication
Section titled “Stream API authentication”Customer Stream requests need both headers:
Authorization: Bearer YOUR_TOKENX-Active-Account: YOUR_ACCOUNT_UUIDThe account must match the token’s verified account.
Verify
Section titled “Verify”For a receiver-bound ingest token, send one known event with the matching sender guide and confirm it in Live Tail. For a read token, make one Stream API request for the intended account and confirm that it returns data without an authentication or scope error.
Troubleshooting
Section titled “Troubleshooting”401means the token is missing, invalid, or no longer active.403means the token lacks the required scope, the account does not match, or an ingest token is bound to another receiver.- If a copied token may have been exposed, delete it and create a replacement instead of reusing it.
Next steps
Section titled “Next steps”Configure the matching receiver or follow the Stream API authentication reference. Review stored tokens regularly and remove those that no longer have an owner or active client.