Skip to content

Way to invalidate tokens generated by /cli-auth? #14679

Open
@alexander-dammeier

Description

@alexander-dammeier

Hi,

quick security question: Is there a way to invalidate a generated token from /cli-auth, so that no API access is possible before the usual expiration of the token?

To my surprise, they are not listed under coder tokens list and also not under /settings/tokens in the UI (v2.14.3).

If there is no way yet, i suggest a new flag like coder tokens list --show-session-tokens or something like that.

This is related to #13990.

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs decisionNeeds a higher-level decision to be unblocked.securityArea: security

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions