Access Management > Access Tokens

Access tokens provide a secure way for external web applications to communicate with your Q-SYS Core through Q-SYS Remote WebSocket Control (QRWC). When Access Control is enabled on the Core, the external application sends its token with each message so Core Manager can verify it before taking action.

From the Access Tokens page, you can create new tokens, monitor active credentials across your system, and revoke tokens when an application no longer requires access.

Note: This page is only visible when Access Control is turned On. To learn how to enable Access Control, see the Access Management > Users topic.

Viewing Access Tokens

The Access Tokens page shows how many tokens exist on the Core and lists them in a table with these columns. If no tokens exist, the table shows no tokens. To find a token, type its name in the Search by token name field. The table filters as you type.

Name

The name given to the token when it was created.

Type

The kind of connection the token is for, such as Q-SYS Remote WebSocket Control (QRWC).

Token

The last four characters of the token. The full token is never shown after it's created.

Username

The user who created the token.

Date Created

When the token was created.

Creating an Access Token

  1. In Q-SYS Core Manager, go to Core Management > Access Management > Access Tokens.

  2. Click + New Token.

  3. Enter a token name. The name must be unique. If another token already has that name, an error message appears.

    Note: Token names must be unique . If the name is already in use, an error message appears.

  4. Click Create.

    Note: A Q-SYS Core supports a maximum of 100 active access tokens. If you attempt to create a 101st token, the error message "Unable to create more than 100 access tokens." displays, and the token is not created. To free up capacity, revoke one or more unused tokens.

  5. A dialog shows the new token. Click Copy, and then store the token somewhere secure.

  6. Close the dialog. The new token appears in the table.

CAUTION: You can only view and copy the token string in the creation dialog. After you close the dialog, the token can't be retrieved again. If you lose the token string or compromised, revoke it and create a new one.

Tip: Give each application or integration its own token, named so you can tell what uses it (for example, Lobby-Dashboard). Then you can revoke access for one application without affecting the others.

Using an Access Token

To connect your web application to the Core via QRWC, pass the generated access token to the QRWC library during the initial connection handshake.

For implementation instructions, code samples, and library options, such as passing the token via apiKey, refer to the Q-SYS Remote WebSocket Control (QRWC) topic

and the

QRWC NPM package documentation.

Revoking Access Tokens

Revoke a token when an application no longer needs access, or if the token may have been exposed.

  1. In the table, select the checkbox next to each token you want to revoke, or select the checkbox in the table header to select all tokens. The Revoke button remains disabled until you select at least one token.

  2. Click Revoke.

  3. In the confirmation dialog, click Revoke.

The tokens are removed from the table. Core Manager disconnects any active WebSocket sessions that use a revoked token.

CAUTION: Revoking a token is permanent and cannot be undone. Any application relying on a revoked token immediately loses connection until reconfigured with a newly generated token.

Role Permissions

Role

View Tokens

Create Tokens

Revoke Tokens

Administrator

✓ ✓ ✓

Technician

✓ x x

Viewer

✓ x x

Custom Role (Full Access)

✓ ✓ ✓

Custom Role (View)

✓ x x

If your user role does not permit creating or revoking tokens, + New Token and Revoke are disabled. To set Access Tokens permissions for a custom role, see the Access Management > Roles topic.

Event Log

Actions taken on the Access Tokens page are recorded in the Event Log. Each recorded entry includes a timestamp and the user who took the action.

Disabling Access Control

When Access Control is toggled Off on the Core:

Note: Before disabling Access Control, revoke all active access tokens. If you re-enable Access Control later, generate new tokens for your external applications.

Q-SYS Reflect

Access tokens can also be viewed, created, and revoked remotely through Q-SYS Reflect for any Core registered to an organization. The interface, procedures, and permissions function identically to local Core Manager.