Skip to main content
An access token identifies your Devolens account and grants permission to call selected Web API methods. You can select several permissions on the same access token, then apply the restrictions supported by those methods.

Which credential do I need?

The RSA public key can be included in your application. Anyone who has an access token can call the methods it allows, so access tokens that can create licenses or perform administrative tasks should stay on systems you control. For an application you distribute to customers, use a separate access token with only the permissions it needs.

Where do I find my RSA public key?

  1. Sign in to the dashboard QuickStart page.
  2. Find Credentials, then RSA Public Key.
  3. Copy the entire public key, including the XML tags, into the public-key parameter used by your SDK example.
The public key needs to belong to the account that issued the license data. Your SDK uses it to check that the data has not been altered. Your application still needs to check the product, expiry, features, and machine binding where applicable, as described in key verification. Your account-specific credentials are displayed on the signed-in dashboard, not on these support pages. If you use a local License Server, follow that guide’s instructions for its public-key configuration.

How do I create an access token?

  1. Open Create Access Token.
  2. Enter a descriptive Name, such as Application activation.
  3. Select the permissions your integration will use. All permission checkboxes start unchecked.
  4. Choose the appropriate Product Lock, Key Lock, and Feature Lock. See the recommended configurations below, then the control reference for details.
  5. Select Create Access Token, then copy and securely store the returned access token. A newly created personal access token is shown only once and cannot be retrieved later.
  6. Supply the access token as the API’s token parameter or the SDK’s token / auth argument.
For testing, you can use the Access Token in the dashboard’s QuickStart Credentials section. It has the Activate and GetKey permissions, but not the Deactivate permission. Before publishing your application, create your own access token with the permissions and restrictions it needs.

Which configuration should I use?

The examples below show which settings to select for common uses. You will need to select them yourself when creating the access token. Replace YOUR_PRODUCT_ID, YOUR_LICENSE_TEMPLATE_ID, and YOUR_ACCESS_TOKEN with your own values where applicable. In the Product Lock dropdown, select the product whose ID is YOUR_PRODUCT_ID.

Application activation and device release

Use YOUR_ACCESS_TOKEN in the SDK’s token / auth argument for the permitted calls. See key verification. If your application uses machine binding, configure the license’s maximum number of machines greater than 0 and perform the appropriate machine check. Permission to activate does not itself enable node locking on every license.

Backend license creation

Call CreateKey with YOUR_ACCESS_TOKEN and ProductId=YOUR_PRODUCT_ID. Keep this access token on your server. Add Add Customer or Get Customers only if the backend creates or looks up customer records; supplying an already-known customer ID does not by itself require those extra calls. For template-based creation, use Create Key From Template instead of Create Key. Set Feature Lock to YOUR_LICENSE_TEMPLATE_ID to restrict the template, or 0 to allow the backend to choose. Add License Template only if the backend also needs to list templates. Use CreateKeyFromTemplate for the request details.

Support administration

For support staff who need to look up licenses, select the Get Key and Get Keys permissions and set Product Lock to the relevant product. Key Lock and Feature Lock can stay at 0. You could name the access token Support license lookup. Keep it in the system your support staff uses, rather than distributing it to customers. Add permissions for the tasks support will actually perform: Customer access reaches account-level records and can expose secrets; the Product Lock is not a customer-record filter. If a different support role handles customer records, use a separate access token with the permissions for that role. Do not select every checkbox as a troubleshooting shortcut.

Can one access token activate and deactivate a license?

Yes. Select both Activate and Deactivate on the same access token. Activate alone does not grant Deactivate, and calling activation successfully does not add new permissions to an access token. Both calls must still satisfy their own parameters and restrictions. For an application that registers and releases devices, use the same product-restricted access token with both checkboxes enabled. See Activate and Deactivate. You can combine other permissions too. For example, an application that checks for updates can have the Get Messages permission on the access token it uses for activation. Separate access tokens are useful when you need different restrictions or want to replace one access token without affecting other uses.

What does each creation control do?

Name and actions

Permission checkboxes

Every checkbox below defaults to unchecked. Checking it grants the operation or group of operations described in its row. Selecting one checkbox does not automatically select other permissions. Some permissions cover multiple methods; User Auth Admin, for example, also permits the normal user-authentication operations. Permissions do not bypass method requirements, product/key restrictions, or subscription requirements. Follow each linked API reference for request parameters and supported restrictions.

License Key

Data Object

These permissions operate on data objects. The applicable product, key, or user scope and any key-bound access token requirements depend on the method variant.

Analytics

Product

Miscellaneous

Customer

Customer records are account-level objects: do not assume that a Product Lock limits customer administration to customers of that product. See each method for the scope of returned license information.

Product Lock, Key Lock, and Feature Lock

For example, selecting your product and leaving Key Lock at 0 lets the enabled license operations work with licenses of that product, subject to each method’s requirements. Locks are not a universal filter on account-level operations. Do not rely on them to restrict unrelated customer, user, reseller, or payment administration.

Negative Key Lock and delegated access tokens

Use a negative Key Lock only for a workflow that requires it. With Key Lock -1, Auth.KeyLock can exchange the parent access token and a supplied product/license key for a child access token bound to that license. The child retains the method permissions and expires one day after creation. -2 gives two days; -N gives N days. The negative setting enables this exchange without a separate checkbox. This does not bind the parent access token to one particular license, and it is not a general fix for permission errors. Follow the relevant data-object method’s key-bound access token instructions when applicable. The separate Get Token authorization workflow gives Key Lock another meaning: a positive value caps the requested child access token lifetime in days. Follow that workflow’s reference rather than applying the normal numeric-license-ID interpretation.

Feature Lock depends on the method

All permissions on one access token share the same lock fields. For example, Feature Lock 7 used as a template restriction also has a different meaning if Activate is enabled on that access token. Use separate access tokens when the operations need different restrictions. Feature Lock does not check whether a license includes the feature your application needs; your application must perform that license check.

How do I edit, replace, or remove an access token?

Use the dashboard Access Tokens page to edit an existing personal access token’s name, permissions, and locks. Changes apply immediately to integrations already using that access token; editing does not reveal its value again. Account locks can prevent editing or removal. If the access token value is lost, create a replacement and update the integrations that use it. Remove the old access token when it is no longer needed. Removing an access token stops future calls that rely on it; it does not change a license or invalidate a signed license file already stored by an application.

Why am I getting a permission or credential error?

See the troubleshooting guide for other errors and the authentication reference for API authentication details.