> ## Documentation Index
> Fetch the complete documentation index at: https://help.cryptolens.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Access tokens and RSA public key

> Find your credentials, understand every access token control, and choose permissions for activation, license creation, and support.

An access token identifies your Devolens account and grants permission to call selected Web API methods. You can select several permissions on the same access token, then apply the restrictions supported by those methods.

## Which credential do I need?

| Value | Purpose | Where to find it |
| - | - | - |
| Access token (`token` or `auth` in examples) | Authorizes API operations. Its permissions determine what a caller can do. | Create one on the dashboard's [Access Tokens page](https://app.cryptolens.io/User/AccessToken#/newtoken), or use the QuickStart access token for initial testing. |
| RSA public key (`RSAPubKey` or `publicKey`) | Verifies the signature on returned license data. It does not authorize API requests or create signatures. | The **Credentials → RSA Public Key** section of the dashboard [QuickStart page](https://app.cryptolens.io/docs/api/v3/QuickStart), while signed in. |
| Product ID (`ProductId`) | Identifies the product whose licenses you are using. | Your product's dashboard page. |
| License key (`Key`) | Identifies the customer's license within a product. | A license on your product's dashboard page, or the license supplied by your customer. |

The RSA public key can be included in your application. Anyone who has an access token can call the methods it allows, so access tokens that can create licenses or perform administrative tasks should stay on systems you control. For an application you distribute to customers, use a separate access token with only the permissions it needs.

## Where do I find my RSA public key?

1. Sign in to the [dashboard QuickStart page](https://app.cryptolens.io/docs/api/v3/QuickStart).
2. Find **Credentials**, then **RSA Public Key**.
3. Copy the entire public key, including the XML tags, into the public-key parameter used by your SDK example.

The public key needs to belong to the account that issued the license data. Your SDK uses it to check that the data has not been altered. Your application still needs to check the product, expiry, features, and machine binding where applicable, as described in [key verification](/examples/key-verification).

Your account-specific credentials are displayed on the signed-in dashboard, not on these support pages. If you use a local [License Server](/feature/license-server/index), follow that guide's instructions for its public-key configuration.

## How do I create an access token?

1. Open [Create Access Token](https://app.cryptolens.io/User/AccessToken#/newtoken).
2. Enter a descriptive **Name**, such as `Application activation`.
3. Select the permissions your integration will use. All permission checkboxes start unchecked.
4. Choose the appropriate **Product Lock**, **Key Lock**, and **Feature Lock**. See the [recommended configurations](#which-configuration-should-i-use) below, then the [control reference](#what-does-each-creation-control-do) for details.
5. Select **Create Access Token**, then copy and securely store the returned access token. A newly created personal access token is shown only once and cannot be retrieved later.
6. Supply the access token as the API's `token` parameter or the SDK's `token` / `auth` argument.

For testing, you can use the **Access Token** in the dashboard's [QuickStart Credentials section](https://app.cryptolens.io/docs/api/v3/QuickStart). It has the **Activate** and **GetKey** permissions, but not the **Deactivate** permission. Before publishing your application, create your own access token with the permissions and restrictions it needs.

## Which configuration should I use?

The examples below show which settings to select for common uses. You will need to select them yourself when creating the access token. Replace `YOUR_PRODUCT_ID`, `YOUR_LICENSE_TEMPLATE_ID`, and `YOUR_ACCESS_TOKEN` with your own values where applicable. In the Product Lock dropdown, select the product whose ID is `YOUR_PRODUCT_ID`.

### Application activation and device release

| Setting | Value |
| - | - |
| Name | `Application activation` |
| Permissions | **Activate**. Add **Deactivate** if the application releases devices; add **Get Key** only if it calls GetKey. Leave other checkboxes unchecked. |
| Product Lock | Product `YOUR_PRODUCT_ID` |
| Key Lock | `0` |
| Feature Lock | `0` initially; choose a returned-field mask if your application should receive less license data. |

Use `YOUR_ACCESS_TOKEN` in the SDK's `token` / `auth` argument for the permitted calls. See [key verification](/examples/key-verification). If your application uses machine binding, configure the license's maximum number of machines greater than `0` and perform the appropriate machine check. Permission to activate does not itself enable node locking on every license.

### Backend license creation

| Setting | Value |
| - | - |
| Name | `Backend license creation` |
| Permissions | **Create Key**. Leave other checkboxes unchecked unless this backend actually calls those methods. |
| Product Lock | Product `YOUR_PRODUCT_ID` |
| Key Lock | `0` |
| Feature Lock | `0` |

Call [CreateKey](/api-reference/generated/CreateKey) with `YOUR_ACCESS_TOKEN` and `ProductId=YOUR_PRODUCT_ID`. Keep this access token on your server. Add **Add Customer** or **Get Customers** only if the backend creates or looks up customer records; supplying an already-known customer ID does not by itself require those extra calls.

For template-based creation, use **Create Key From Template** instead of Create Key. Set Feature Lock to `YOUR_LICENSE_TEMPLATE_ID` to restrict the template, or `0` to allow the backend to choose. Add **License Template** only if the backend also needs to list templates. Use [CreateKeyFromTemplate](/api-reference/generated/CreateKeyFromTemplate) for the request details.

### Support administration

For support staff who need to look up licenses, select the **Get Key** and **Get Keys** permissions and set **Product Lock** to the relevant product. **Key Lock** and **Feature Lock** can stay at `0`. You could name the access token `Support license lookup`. Keep it in the system your support staff uses, rather than distributing it to customers.

Add permissions for the tasks support will actually perform:

| Support task | Additional permission |
| - | - |
| Release an activated device | Deactivate |
| Renew a license | Extend License |
| Block or restore access | Block Key and/or Unblock Key |
| Update license notes | Change Notes |
| Reassign a license to a customer | Change Customer |
| Look up customer records or secrets | Get Customers |
| Update customer details | Edit Customer |

Customer access reaches account-level records and can expose secrets; the Product Lock is not a customer-record filter. If a different support role handles customer records, use a separate access token with the permissions for that role. Do not select every checkbox as a troubleshooting shortcut.

<span id="can-one-token-activate-and-deactivate-a-license" />

## Can one access token activate and deactivate a license?

**Yes. Select both Activate and Deactivate on the same access token.** Activate alone does not grant Deactivate, and calling activation successfully does not add new permissions to an access token.

Both calls must still satisfy their own parameters and restrictions. For an application that registers and releases devices, use the same product-restricted access token with both checkboxes enabled. See [Activate](/api-reference/generated/Activate) and [Deactivate](/api-reference/generated/Deactivate).

You can combine other permissions too. For example, an application that checks for updates can have the **Get Messages** permission on the access token it uses for activation. Separate access tokens are useful when you need different restrictions or want to replace one access token without affecting other uses.

## What does each creation control do?

### Name and actions

| Control | Initial value | Effect |
| - | - | - |
| Name | Blank | Required descriptive label, up to 30 characters. This is not the credential you pass to the API. |
| Create Access Token | Button | Creates an access token with the selected permissions and restrictions and displays its value once. |
| Back to Access Tokens | Link | Returns to the access token list without submitting the creation form. |

### Permission checkboxes

Every checkbox below defaults to **unchecked**. Checking it grants the operation or group of operations described in its row. Selecting one checkbox does not automatically select other permissions. Some permissions cover multiple methods; **User Auth Admin**, for example, also permits the normal user-authentication operations.

Permissions do not bypass method requirements, product/key restrictions, or subscription requirements. Follow each linked API reference for request parameters and supported restrictions.

#### License Key

| Checkbox | Effect when checked |
| - | - |
| [Activate](/api-reference/generated/Activate) | Activates a license for a machine code and retrieves license information. Machine registration depends on the license's configuration. |
| [Deactivate](/api-reference/generated/Deactivate) | Removes an activation for a machine code, subject to the method's requirements. |
| [Add Feature](/api-reference/generated/AddFeature) | Enables one of the license's feature flags. |
| [Block Key](/api-reference/generated/BlockKey) | Blocks an existing license. |
| [Create Key](/api-reference/generated/CreateKey) | Creates a license with the supplied properties. |
| [Create Trial Key](/api-reference/generated/CreateTrialKey) | Creates or retrieves a trial for a machine code. The default trial duration is 15 days; Feature Lock can change it. |
| [Create Key From Template](/api-reference/generated/CreateKeyFromTemplate) | Creates a license using a license template. Feature Lock can restrict the template ID. |
| [Get Key](/api-reference/generated/GetKey) | Retrieves an existing license's information without registering a new activation. |
| [Extend License](/api-reference/generated/ExtendLicense) | Extends a license's expiration date. |
| [Remove Feature](/api-reference/generated/RemoveFeature) | Disables one of the license's feature flags. |
| [Unblock Key](/api-reference/generated/UnblockKey) | Unblocks an existing license. |
| [Machine Lock Limit](/api-reference/generated/MachineLockLimit) | Changes the license's maximum number of machines. |
| [Change Notes](/api-reference/generated/ChangeNotes) | Changes the license's notes. |
| [Change Reseller](/api-reference/generated/ChangeReseller) | Changes the reseller associated with a license. |
| [Change Customer](/api-reference/generated/ChangeCustomer) | Changes the customer associated with a license. |
| [Trial Activation](/api-reference/generated/TrialActivation) | Changes whether the license starts its validity countdown on activation. This does not create a trial license. |

#### Data Object

These permissions operate on [data objects](/api-reference/generated/Data). The applicable product, key, or user scope and any key-bound access token requirements depend on the method variant.

| Checkbox | Effect when checked |
| - | - |
| [Add Data Object](/api-reference/generated/AddDataObject) | Creates a data object with a name and string/integer values. |
| [Increment Int Value](/api-reference/generated/IncrementIntValue) | Increases a data object's integer value. Feature Lock can cap the increment amount. |
| [Decrement Int Value](/api-reference/generated/DecrementIntValue) | Decreases a data object's integer value. |
| [Set Int Value](/api-reference/generated/SetIntValue) | Replaces a data object's integer value. |
| [Set String Value](/api-reference/generated/SetStringValue) | Replaces a data object's string value. |
| [List Data Objects](/api-reference/generated/ListDataObjects) | Retrieves data objects for the requested scope. |
| [Remove Data Object](/api-reference/generated/RemoveDataObject) | Deletes a data object. |

#### Analytics

| Checkbox | Effect when checked |
| - | - |
| [Usage Analytics](/api-reference/generated/AI#usage-analytics) | Reads aggregated usage analytics, including daily usage, country aggregates, key summaries, devices, and activity buckets. These methods also require an eligible subscription. |
| [Register Event](/api-reference/generated/RegisterEvent) | Submits application usage events. |
| [Get Events](/api-reference/generated/GetEvents) | Retrieves registered application usage events. |
| [Get Object Log](/api-reference/generated/GetObjectLog) | Reads the log of object creation, editing, and removal. |
| [Get Web API Log](/api-reference/generated/GetWebAPILog) | Reads the Web API event log, including license and data-object activity recorded there. |

#### Product

| Checkbox | Effect when checked |
| - | - |
| [Get Keys](/api-reference/generated/GetKeys) | Lists and searches license keys within a product. |
| [Get Products](/api-reference/generated/GetProducts) | Retrieves product information. |

#### Miscellaneous

| Checkbox | Effect when checked |
| - | - |
| [Get Token](/api-reference/generated/GetToken) | Enables the delegated authorization workflow for obtaining an access token on behalf of an authorizing user, including requests for the challenge and access token. It is not needed to use an existing access token for activation. |
| [Payment Form](/api-reference/generated/PFCreateSession) | Creates payment-form sessions and permits viewing session data. This concerns payments from your customers. |
| [Get Messages](/api-reference/generated/GetMessages) | Retrieves messages from a channel, for example application update notifications. |
| [Edit Messages](/api-reference/generated/Message) | Creates and removes messages. |
| [Subscription](/api-reference/generated/Subscription) | Permits recording usage through the recurring-billing API for your customers. It does not manage your own Devolens subscription. |
| [Reseller](/api-reference/generated/Reseller) | Permits the reseller API operations, including listing, adding, editing, removing resellers, and retrieving their customers. |
| [License Template](/api-reference/generated/GetLicenseTemplates) | Retrieves license templates. Creating a license from a template requires the separate Create Key From Template permission. |
| [User Auth Normal](/api-reference/generated/UserAuth) | Permits user login to retrieve associated licenses and password changes with the user's current password. |
| [User Auth Admin](/api-reference/generated/UserAuth) | Permits normal user-authentication operations plus registration, customer association/dissociation, listing/removing users, password-reset tokens, and administrative password changes. Keep this permission on trusted systems. |

#### Customer

Customer records are account-level objects: do not assume that a Product Lock limits customer administration to customers of that product. See each method for the scope of returned license information.

| Checkbox | Effect when checked |
| - | - |
| [Add Customer](/api-reference/generated/AddCustomer) | Creates a customer record. |
| [Get Customers](/api-reference/generated/GetCustomers) | Retrieves customer records. `ModelVersion=2` or `3` also returns their secrets. |
| [Remove Customer](/api-reference/generated/RemoveCustomer) | Removes a customer record. |
| [Edit Customer](/api-reference/generated/EditCustomer) | Updates a customer record. |
| [Get Customer Licenses](/api-reference/generated/GetCustomerLicenses) | Retrieves a customer's licenses using the customer ID. |
| [Get Customer Licenses By Secret](/api-reference/generated/GetCustomerLicenses) | Retrieves a customer's licenses using their secret. This permission does not retrieve the secret itself. |

### Product Lock, Key Lock, and Feature Lock

| Control | Default | Effect |
| - | - | - |
| Product Lock | **Any** (`0`) | Where the API method supports this restriction, `0` permits all account products; selecting a product restricts calls to that product. It does not grant any method permissions. |
| Key Lock | `0` | For methods that check license access, `0` leaves the access token unrestricted to a particular license; a positive value restricts it to that license's numeric ID (`GlobalId`), not its license-key string. Other restrictions still apply. Negative values enable the key-bound access token workflow described below. |
| Feature Lock | `0` | Leaves the method's normal behavior in place without a feature override from the access token. Nonzero values have different meanings for different methods, as listed below. |

For example, selecting your product and leaving Key Lock at `0` lets the enabled license operations work with licenses of that product, subject to each method's requirements. Locks are not a universal filter on account-level operations. Do not rely on them to restrict unrelated customer, user, reseller, or payment administration.

<span id="negative-key-lock-and-delegated-tokens" />

#### Negative Key Lock and delegated access tokens

Use a negative Key Lock only for a workflow that requires it. With Key Lock `-1`, [Auth.KeyLock](/api-reference/generated/KeyLock) can exchange the parent access token and a supplied product/license key for a child access token bound to that license. The child retains the method permissions and expires one day after creation. `-2` gives two days; `-N` gives `N` days. The negative setting enables this exchange without a separate checkbox.

This does not bind the parent access token to one particular license, and it is not a general fix for permission errors. Follow the relevant data-object method's key-bound access token instructions when applicable.

The separate [Get Token authorization workflow](/api-reference/generated/GetToken) gives Key Lock another meaning: a positive value caps the requested child access token lifetime in days. Follow that workflow's reference rather than applying the normal numeric-license-ID interpretation.

#### Feature Lock depends on the method

| Method | Meaning of Feature Lock |
| - | - |
| [Add Feature](/api-reference/generated/AddFeature) / [Remove Feature](/api-reference/generated/RemoveFeature) | A feature number from `1` to `8` restricts which flag may be changed; `0` leaves all feature numbers available to those permitted methods. |
| [Activate](/api-reference/generated/Activate) / [Get Key](/api-reference/generated/GetKey) | A positive returned-field mask controls which fields are hidden, overriding the request's `FieldsToReturn`. Use the field values in the method reference; `0` leaves the request's setting in effect. |
| [Create Trial Key](/api-reference/generated/CreateTrialKey) | A positive number sets the trial duration in days; `0` leaves the 15-day default. |
| [Create Key From Template](/api-reference/generated/CreateKeyFromTemplate) | A nonzero value restricts creation to that license template ID; `0` leaves template choice unrestricted by this field. |
| [Increment Int Value](/api-reference/generated/IncrementIntValue) | A nonzero value caps the increment amount. For example, `1` permits an increment of at most `1`; `0` supplies no cap from the access token. |

All permissions on one access token share the same lock fields. For example, Feature Lock `7` used as a template restriction also has a different meaning if Activate is enabled on that access token. Use separate access tokens when the operations need different restrictions. Feature Lock does not check whether a license includes the feature your application needs; your application must perform that license check.

<span id="how-do-i-edit-replace-or-remove-a-token" />

## How do I edit, replace, or remove an access token?

Use the dashboard [Access Tokens page](https://app.cryptolens.io/User/AccessToken#/) to edit an existing personal access token's name, permissions, and locks. Changes apply immediately to integrations already using that access token; editing does not reveal its value again. Account locks can prevent editing or removal.

If the access token value is lost, create a replacement and update the integrations that use it. Remove the old access token when it is no longer needed. Removing an access token stops future calls that rely on it; it does not change a license or invalidate a signed license file already stored by an application.

## Why am I getting a permission or credential error?

| Symptom | What to check |
| - | - |
| Activate succeeds but Deactivate returns `Access denied` | Enable **Deactivate** on that personal access token, or replace it with an access token that has both permissions. The pre-generated QuickStart access token does not include Deactivate. |
| Another method returns `Access denied` | Check that method's permission and its supported Product, Key, and Feature Lock restrictions. An access token permitting one method does not automatically permit another. |
| `Unable to authenticate` | Check the access token value and that the account has API access. Do not put the RSA public key or license key in the access token field. |
| `Not enough permission and/or key not found.` | Check the product, license, method permission, and locks. Some data-object variants require a key-bound access token; follow that method's reference and [Auth.KeyLock](/api-reference/generated/KeyLock) where specified. Setting Key Lock to `-1` is not a universal remedy. |
| Signature verification fails | Check that the entire RSA public key belongs to the account issuing the signed response and that the response uses the format expected by your SDK. Adding access token permissions does not correct a wrong public key. |

See the [troubleshooting guide](/getting-started/troubleshooting-guide) for other errors and the [authentication reference](/api-reference/generated/Auth) for API authentication details.
