Client tokens
The PortLark client authenticates with a token, not with your password. Tokens can be revoked at any time without changing your password.
Kinds of credentials
| Credential | Created by | Can connect | Stored on the computer at |
|---|---|---|---|
| Client token | portlark setup, or manually in Dashboard → Client Tokens | Your tunnels | ~/.config/portlark/config.json (when created by setup) |
| Agent credential | Browser approval (portlark agent login) or a one-time code (portlark agent redeem) | The one tunnel you approved | The portlark/agent folder in your user configuration directory |
See Files and locations in the CLI reference for the exact paths on each operating system.
Create a token manually
- Open Dashboard → Client Tokens and create a token with a name you will recognize, such as the computer's name.
- Copy it immediately. A new token is shown only once.
- Use it with the CLI:
portlark --token <client-token> --tunnel <tunnel-id>
Store tokens like passwords. Never commit them to source control, paste them into chats or include them in support requests.
Revoke a token
Revoke a token in Dashboard → Client Tokens when a computer is lost, sold or no longer needs access, or when a token may have leaked.
- New connections with the token are rejected immediately.
- Tunnels that are already connected close within about two minutes.
- Your tunnels are not deleted. Run
portlark setupon a trusted computer to create a new token.
Expired access (an ended trial or subscription) and account suspension also prevent connections, even with a valid token.
Last updated
Report an issue with this page