Generate, rotate, and manage your workspace token.
Available Plans
  • free

This guide covers how to generate, rotate, and manage your workspace token.

Overview

A workspace token uniquely identifies your RudderStack workspace. Your self-hosted data plane uses this token to read its source-destination configuration from the RudderStack-hosted control plane.

Availability and access

  • Workspace tokens are available only in the RudderStack Free and Open Source plans.
  • Only organization admins can generate and manage workspace tokens.

Generate a workspace token

  1. In the RudderStack dashboard, go to Settings > Workspace > Security.
  2. Click New token.
Generate workspace token modal
  1. Under Set token expiry, select an expiry period: 30 days, 60 days, 90 days, 180 days, or Never. By default, the expiry period is set to 180 days. Select Never only if the token must remain valid until you manually revoke it.
  2. Carefully review the Security acknowledgement and select all the checkboxes. The Generate token button stays disabled until you do.
If you selected Never as the expiry period, make sure to select the additional never-expiry acknowledgement as well.
Set token expiry
  1. Generate the token and copy its value immediately.
Copy workspace token value

Save the token

The workspace token appears only once in plain text, immediately after generation. Save it in a secure secrets manager before closing the modal.

RudderStack stores only a SHA-512 hash and a display mask after generation, so neither you nor RudderStack Support can retrieve the plaintext value later. If you lose it, you will need to generate a new token.

Note that:

  • New tokens use the format rs_wt_v1_<base64url>.
  • After generation, the dashboard displays them as rs_wt_v1_**********<last 6 characters>.
Workspace token after generation

Check token status

The pill next to the Current token and Previous token headers shows the status of your tokens:

StatusMeaning
ActiveValid — more than 30 days remaining or no expiry set
Expiring Soon30 days or fewer until expiry
ExpiringSuperseded by a newer token and in its grace period — the card shows the time remaining and an Auto-deletes date

Important considerations

  • Expired tokens are removed from the list. A data plane using an expired token cannot read workspace configuration.
  • Banners and modals appear when a token is in its grace period or has 30 days or fewer until expiry. Organization admins also receive email 30, 14, 7, and 1 days before expiry, when the token expires, and about 2 hours before a grace period ends.

Rotate a workspace token

The Regenerate token button creates a new token — it doesn’t reveal or update an existing workspace token. If the button isn’t shown, the workspace is at its token limit.

Creating the new token starts the previous token’s grace period of 24 hours. Both the new and previous tokens authenticate during this window, so you can migrate without downtime.

Rotation can shorten the previous token’s validity. For example, a token with 180 days remaining stops working at the end of its grace period (24 hours) once you generate a new token.

To rotate a token safely:

  1. Generate a new token and securely save the show-once value.
  2. Update the token value in your data plane deployment.
  3. Restart the data plane.
  4. Verify that the data plane can read the workspace configuration before the overlap window ends.
Regenerate workspace token

Delete a workspace token

Delete a token to revoke it immediately. Any data plane still using that token loses access to the workspace configuration, so verify that your deployment uses another valid token first.

Audit logs record token creation and deletion events.

Delete workspace token

Workspace token limits

A workspace can have at most two non-expired workspace tokens — expired tokens do not count toward this limit.

When the workspace is at the limit, the Regenerate token button disappears and the Security tab shows “Maximum tokens reached. Delete one token before generating a new one. Both tokens are currently valid.”

During a rotation, the previous token still occupies a slot, so you stay at the limit until the grace period ends or you click Delete now on the in-grace token card.

Existing workspace tokens

Existing (legacy) workspace tokens continue to work without any action.

For better security, RudderStack recommends generating a new token, updating your data plane, and retiring the migrated token by following the rotation steps.

Add the token to your data plane

Add the generated token to your deployment by following the relevant setup guide:

Workspace tokens vs. access tokens

A workspace token authenticates a self-hosted data plane so it can read workspace configuration. Don’t use it to call RudderStack APIs.

  • A Service Access Token authenticates applications that access RudderStack APIs at the organization or workspace level.
  • A Personal Access Token is tied to an individual user and authenticates that user’s API requests.

Questions? Let's figure it out together.

Join the RudderStack Slack community to connect with other users, customers, and the RudderStack team — or reach out for direct support.