Access Management > Access Tokens
Access tokens provide a secure way for external web applications to communicate with your Q-SYS Core through Q-SYS Remote WebSocket Control (QRWC). When Access Control is enabled on the Core, the external application sends its token with each message so Core Manager can verify it before taking action.
From the Access Tokens page, you can create new tokens, monitor active credentials across your system, and revoke tokens when an application no longer requires access.
Note: This page is only visible when Access Control is turned On. To learn how to enable Access Control, see the Access Management > Users topic.
Viewing Access Tokens
The Access Tokens page shows how many tokens exist on the Core and lists them in a table with these columns. If no tokens exist, the table shows no tokens. To find a token, type its name in the Search by token name field. The table filters as you type.
Name
The name given to the token when it was created.
Type
The kind of connection the token is for, such as Q-SYS Remote WebSocket Control (QRWC).
Token
The last four characters of the token. The full token is never shown after it's created.
Username
The user who created the token.
Date Created
When the token was created.
Creating an Access Token
-
In Q-SYS Core Manager, go to Core Management > Access Management > Access Tokens.
-
Click + New Token.
-
Enter a token name. The name must be unique. If another token already has that name, an error message appears.
Note: Token names must be unique . If the name is already in use, an error message appears.
-
Click Create.
Note: A Q-SYS Core supports a maximum of 100 active access tokens. If you attempt to create a 101st token, the error message "Unable to create more than 100 access tokens." displays, and the token is not created. To free up capacity, revoke one or more unused tokens.
-
A dialog shows the new token. Click Copy, and then store the token somewhere secure.
-
Close the dialog. The new token appears in the table.
CAUTION: You can only view and copy the token string in the creation dialog. After you close the dialog, the token can't be retrieved again. If you lose the token string or compromised, revoke it and create a new one.
Tip: Give each application or integration its own token, named so you can tell what uses it (for example, Lobby-Dashboard). Then you can revoke access for one application without affecting the others.
Using an Access Token
To connect your web application to the Core via QRWC, pass the generated access token to the QRWC library during the initial connection handshake.
For implementation instructions, code samples, and library options, such as passing the token via apiKey, refer to the Q-SYS Remote WebSocket Control (QRWC) topic
and the QRWC NPM package documentation.
Revoking Access Tokens
Revoke a token when an application no longer needs access, or if the token may have been exposed.
-
In the table, select the checkbox next to each token you want to revoke, or select the checkbox in the table header to select all tokens. The Revoke button remains disabled until you select at least one token.
-
Click Revoke.
-
In the confirmation dialog, click Revoke.
The tokens are removed from the table. Core Manager disconnects any active WebSocket sessions that use a revoked token.
CAUTION: Revoking a token is permanent and cannot be undone. Any application relying on a revoked token immediately loses connection until reconfigured with a newly generated token.
Role Permissions
| Role |
View Tokens |
Create Tokens |
Revoke Tokens |
|---|---|---|---|
|
Administrator |
✓ | ✓ | ✓ |
|
Technician |
✓ | x | x |
|
Viewer |
✓ | x | x |
|
Custom Role (Full Access) |
✓ | ✓ | ✓ |
|
Custom Role (View) |
✓ | x | x |
If your user role does not permit creating or revoking tokens, + New Token and Revoke are disabled. To set Access Tokens permissions for a custom role, see the Access Management > Roles topic.
Event Log
Actions taken on the Access Tokens page are recorded in the Event Log. Each recorded entry includes a timestamp and the user who took the action.
-
Token created: QRWC token "<token-name>" created.
-
Token revoked: QRWC token "<token-name>" revoked. If you revoke multiple tokens at once, a distinct entry is logged for each token.
Disabling Access Control
When Access Control is toggled Off on the Core:
-
The Access Tokens page is hidden from the navigation menu.
-
External web applications connecting via QRWC are no longer required to authenticate with an access token.
Note: Before disabling Access Control, revoke all active access tokens. If you re-enable Access Control later, generate new tokens for your external applications.
Q-SYS Reflect
Access tokens can also be viewed, created, and revoked remotely through Q-SYS Reflect for any Core registered to an organization. The interface, procedures, and permissions function identically to local Core Manager.
