# API Tokens

**Category:** [Security & Access](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/security-access)
**Updated:** 2026-08-19

## What are API tokens?

API tokens provide server-to-server access to TotalCtrl's API for integrations and automation scripts.

## Creating a token

  
- Go to **Settings → API tokens → New token**.
  
- Give the token a descriptive name.
  
- Copy the **token key** and **token secret** — the secret is shown only once.

## Revoking a token

If a token is compromised, go to **Settings → API tokens**, find the token, and click **Revoke**. The token stops working immediately.

---

## Related Articles

- [Single Sign-On (SSO)](https://help.totalctrl.app/en-US/articles/single-sign-on-sso)
- [Setting Up SSO with Okta or a Custom OIDC Provider](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-okta-or-a-custom-oidc-provider)
- [Two-Factor Authentication (2FA)](https://help.totalctrl.app/en-US/articles/two-factor-authentication-2fa)
- [Setting Up SSO with Google Workspace](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-google-workspace)
- [Setting Up SSO with Microsoft / Azure AD](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-microsoft-azure-ad)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)