> ## Documentation Index
> Fetch the complete documentation index at: https://help.cryptolens.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication & Authorization

> Web API 3 provides a new way of communicating with Cryptolens. Instead of having different access levels (where permission is given on a global level), Web API 3 provides a uniform way of authentication and authorization...

### Introduction

Web API 3 provides a new way of communicating with Cryptolens.
Instead of having different access levels (where permission is given on a global level),
Web API 3 provides a uniform way of authentication and authorization (*please see the explanation of terms below*).

The access token is an additional parameter that you have to add to each request, i.e. **token=\{accesstoken}**. For example

```text theme={null}
https://api.cryptolens.io/api/key/GetKey?token={accesstoken}&ProductId=1234&Key=MUYVD-LSEBY-CXHRQ-XFAGY&Sign=True
```

### Access Tokens

An access token is an easy way of **identifying yourself to Cryptolens** and ensuring that only a
**specified scope of permissions** is given.

You can think of access tokens as your **login credentials** that are **restricted to a certain scope** of methods (in the Web API).
Here's an example of an access token.

```text theme={null}
WyI0IiwiM0l0SlRwQTFTSUNDcXNXQXhsdG8ra0ZmQUU5L0wrVGZRUUQrZ1lybSJd
```

Use your own access-token value in requests; its name is only a descriptive label.

You can manage your access tokens on the [Access Token page](https://app.cryptolens.io/User/AccessToken).

Note, an access token will only be shown once. There is no way of retrieving it once generated.

For every control, default, and recommended configuration, see the [access-token and RSA public-key guide](https://help.cryptolens.io/getting-started/access-token).
Your RSA public key verifies signed license data; it does not authorize API calls. Find it under Credentials on the signed-in dashboard QuickStart page, following the instructions in the guide.

Please make sure that you treat each access token as your personal password. Although an access token has a restricted scope, it will be able to access products even if they are not set to IsPublic.

[Create an Access Token](https://app.cryptolens.io/User/AccessToken)

### Scopes

A scope is a way of telling Cryptolens **what an access token is allowed to do**. It allows you to specify the **allowed methods**
in Web API 3 and if you want to restrict it to a **certain product or key**. Let's look at them more in detail!

#### Method Lock

Permission checkboxes start unchecked. Select the permissions your integration needs; a token can have more than one permission.
Each checkbox grants its documented operation or group of operations. For example, Extend License permits extending a license's expiration date.
Some permissions cover multiple methods, such as User Auth Admin.

**One token can activate and deactivate a license when both Activate and Deactivate are selected.**
Activate alone does not grant Deactivate. The pre-generated QuickStart token permits Activate and GetKey, but not Deactivate.
The requested operation must still satisfy its other parameters and restrictions.

#### Product, Key or Feature Lock

The lock fields default to **0**; Product Lock displays this as **Any**. They restrict permitted operations where the method supports that restriction; they do not grant method permissions.

* **Product Lock:** select a product to restrict supported calls to its product ID. A value of 0 does not restrict the token to one product.
* **Key Lock:** for methods that check license access, a positive value restricts access to the license's numeric ID (GlobalId), not its license-key string. A value of 0 does not restrict access to one license. Negative values enable the [Auth.KeyLock workflow](/api-reference/generated/KeyLock): -1 generates a license-bound child token valid for one day, -2 for two days, and so on, retaining the method permissions. The separate [Get Token authorization workflow](/api-reference/generated/GetToken) uses Key Lock to limit child-token lifetime instead; follow its method-specific instructions.
* **Feature Lock:** its meaning depends on the method. It restricts the feature number for AddFeature/RemoveFeature, supplies a returned-field mask for Activate/GetKey, sets trial days for CreateTrialKey, restricts the template ID for CreateKeyFromTemplate, or caps the increment amount for IncrementIntValue. A value of 0 leaves the method's normal behavior without that token-level override.

All permissions on one token share its lock values. Use separate tokens when operations need different restrictions.
Product and Key locks are not a universal filter on account-level customer, user, reseller, or payment operations; check the relevant method reference.

### Explanation of Terms

* **Authentication** - It's a way of identifying yourself to Cryptolens, i.e. so that Cryptolens knows who is performing the request
* **Authorization** - It's a way of making sure that only the desired permission is given to something.
