Client tokens

The PortLark client authenticates with a token, not with your password. Tokens can be revoked at any time without changing your password.

Kinds of credentials

CredentialCreated byCan connectStored on the computer at
Client tokenportlark setup, or manually in Dashboard → Client TokensYour tunnels~/.config/portlark/config.json (when created by setup)
Agent credentialBrowser approval (portlark agent login) or a one-time code (portlark agent redeem)The one tunnel you approvedThe portlark/agent folder in your user configuration directory

See Files and locations in the CLI reference for the exact paths on each operating system.

Create a token manually

  1. Open Dashboard → Client Tokens and create a token with a name you will recognize, such as the computer's name.
  2. Copy it immediately. A new token is shown only once.
  3. Use it with the CLI:
portlark --token <client-token> --tunnel <tunnel-id>

Store tokens like passwords. Never commit them to source control, paste them into chats or include them in support requests.

Revoke a token

Revoke a token in Dashboard → Client Tokens when a computer is lost, sold or no longer needs access, or when a token may have leaked.

  • New connections with the token are rejected immediately.
  • Tunnels that are already connected close within about two minutes.
  • Your tunnels are not deleted. Run portlark setup on a trusted computer to create a new token.

Expired access (an ended trial or subscription) and account suspension also prevent connections, even with a valid token.

Last updated

Report an issue with this page