FerryDocs

Tokens and secrets

Give each tool its own API token, and replace a token or a secret immediately when it leaks.

Edit on GitHub
Your CLIits own tokenCIits own tokenA scriptits own tokenFerry API

Each tool has its own token. Each token gives full access.

1 / 3

The checklist

  • Give its own token. Create a named API token with an expiry for each pipeline or script. Do not share the . Then you can revoke one token and leave the others.
  • Use secrets for hooks. Set a random --github-webhook-secret.
  • Revoke a leaked token. Use the table below.

If a secret leaks

SecretWhat to do
An API tokenRevoke it under Server → Account in the dashboard. It stops immediately.
The server tokenStop ferryd, delete <data-dir>/api_token and start ferryd again. It makes a new token.
A token from --api-token or FERRY_API_TOKENChange the value.
The passwordChange it under Server → Account. Ferry signs out each other browser.
A Rotate it with ferry deploy-hook rotate NAME.

On this page