The server token
The server token is an API token that ferryd makes for scripts on the server itself.
At its first start, ferryd makes the server token. It writes the token to the file api_token.
FERRY_TOKEN="$(cat /var/lib/ferry/api_token)" ferry servicesferryd has a token of its own: the server token. It is for scripts on the server itself. It has the same access as the other API tokens.
What is different
| Server token | Other tokens | |
|---|---|---|
| Where it is | <data-dir>/api_token, mode 0600 | The dashboard shows it one time |
| In the list of the dashboard | No | Yes |
| Revoke in the dashboard | No | Yes |
ferryd never prints the server token.
Replace the server token
Use one of these two procedures:
- Restart
ferrydwith a new--api-token. - Stop
ferryd. Delete<data-dir>/api_token. Startferrydagain: it makes a new token.
Then give the new token to each program that used the old token.
--api-token or FERRY_API_TOKEN sets the server token. ferryd then does not use the file. ferryd --help does not show the value from the environment.
The server token authenticates the API like the other tokens. Thus the CLI logins and the CI jobs that use it continue to work.
ferryd hashes both values with SHA-256. Then it compares them with no early exit. The time of the comparison tells nothing about the token.