Skip to content
Back to Knowledge Base

How to Create and Manage Device Tokens

Applies to CoCoCo platform v1.0.0-rc.31. Every step below was run on that version. Connecting a real device with the issued credentials is not part of that test.

A Device Token gives a Device the credentials it uses to publish to CoCoCo over MQTT. The broker requires a client certificate, so issuing a token issues one: the client certificate and client key are what authenticate the Device. They are shown only once.

  • The Device must have an MQTT protocol (inbound or outbound). Only then does its page show Connection & Tokens. See How to Add a Device.
  • You need permission to create device tokens (device_token:write), and to revoke them (device_token:revoke).
  1. In the sidebar, under IoT, click Devices, then open the Device.
  2. In Connection & Tokens, click Issue token. The dialog Issue device token opens.
  3. Enter a Name, for example press-1 bridge. Description and Expires are optional.
  4. Click Issue token. The dialog Token issued opens and shows:
    • MQTT URL — the broker address the Device connects to
    • Suggested client ID — the token ID. Use it as the MQTT client ID
    • under mTLS certificates: Client certificate, Client key, Server CA and Tenant CA
  5. Copy every value now and store it where the Device’s software can use it. Nothing here can be read back later — if it is lost, revoke the token and issue another.
  6. Click I have copied them at the bottom of the dialog, or press Esc.

The token is now listed with the status Active, together with its creation date, expiry and when it was last used.

  1. In Connection & Tokens, click Revoke next to the token.
  2. Read the confirmation. It says that the token’s certificate is revoked too, so a device using it stops connecting immediately.
  3. Click Revoke token.

The token stays in the list with the status Revoked.