Back to Knowledge Base
How to Create and Manage Device Tokens
Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version. Connecting a real device with the issued credentials is not part of that test.
What is a Device Token?
Section titled “What is a Device Token?”A Device Token gives a Device the credentials it uses to publish to CoCoCo over MQTT. The broker requires a client certificate, so issuing a token issues one: the client certificate and client key are what authenticate the Device. They are shown only once.
Before you start
Section titled “Before you start”- The Device must have an MQTT protocol (inbound or outbound). Only then does its page show Connection & Tokens. See How to Add a Device.
- You need permission to create device tokens (
device_token:write), and to revoke them (device_token:revoke).
Issue a token
Section titled “Issue a token”- In the sidebar, under IoT, click Devices, then open the Device.
- In Connection & Tokens, click Issue token. The dialog Issue device token opens.
- Enter a Name, for example
press-1 bridge. Description and Expires are optional. - Click Issue token. The dialog Token issued opens and shows:
- MQTT URL — the broker address the Device connects to
- Suggested client ID — the token ID. Use it as the MQTT client ID
- under mTLS certificates: Client certificate, Client key, Server CA and Tenant CA
- Copy every value now and store it where the Device’s software can use it. Nothing here can be read back later — if it is lost, revoke the token and issue another.
- Click I have copied them at the bottom of the dialog, or press Esc.
The token is now listed with the status Active, together with its creation date, expiry and when it was last used.
Revoke a token
Section titled “Revoke a token”- In Connection & Tokens, click Revoke next to the token.
- Read the confirmation. It says that the token’s certificate is revoked too, so a device using it stops connecting immediately.
- Click Revoke token.
The token stays in the list with the status Revoked.