createprovisioningtoken deprecated
PACKAGE: open-xchange-admin
NAME
createprovisioningtoken - creates a provisioning token for a context, or a cross-context token for several.
SYNOPSIS
createprovisioningtoken [OPTION]...
DESCRIPTION
This command line tool creates a provisioning token, the bearer credential an automated client authenticates with instead of an administrator's password - an identity provider driving the SCIM endpoint or a script driving the provisioning API, for instance. A token is bound to one scope and opens that one interface and nothing else.
Given a context (-c), the token is bound to that context. Given several contexts (--contexts), a cross-context token is created that opens every one of them at once; it is stored installation-wide, and only the master administrator or a reseller administrator owning every one of the contexts may create it, and only where MASTER_ACCOUNT_OVERRIDE lets an administrator reach into a context at all. A context administrator can never create a cross-context token.
The tool prints the identifier and the secret. The secret is shown this once: only its hash is stored, so a lost secret cannot be recovered; revoke the token and create a new one.
In a multi-site installation, run the tool on an admin pod of the site the context belongs to: unlike the site-aware provisioning tools, it does not forward the call to another site.
OPTIONS
-c, --contextid contextid : The context the token is bound to. Either this or --contexts is mandatory.
--contexts contextids : The contexts a cross-context token opens, comma-separated, at least two distinct ones. Either this or -c is mandatory.
--label label : What the token is for, for example the identity provider using it; at most 128 characters. Mandatory.
--scope scope : The interface the token opens: scim for the SCIM endpoint, provisioning for the provisioning API. Defaults to scim for a token bound to a context. Mandatory together with --contexts: a cross-context token has no default, so that moving a client from -c to --contexts cannot change what the token opens without saying so.
--expires date : When the token expires: a date as yyyy-MM-dd, meaning midnight UTC at its start, or a date and time with offset such as 2027-01-01T12:00:00Z. It has to lie in the future. Without, the token does not expire.
-A, --adminuser admin : Administrator name for authentication. For a token bound to a context: the context administrator, a reseller administrator owning the context, or the master administrator where MASTER_ACCOUNT_OVERRIDE permits it. For a cross-context token: the master administrator, or a reseller administrator owning every one of the contexts, and only where MASTER_ACCOUNT_OVERRIDE permits it. Optional, depending on your configuration.
-P, --adminpass adminPassword : Administrator password for authentication. Optional, depending on your configuration.
-h, --help : Prints a help text.
--environment : Show info about commandline environment.
--nonl : Remove all newlines (\n) from output.
--responsetimeout : The optional response timeout in seconds when reading data from server (default: 0s; infinite).
EXAMPLES
createprovisioningtoken -A contextAdmin -P secret -c 1138 --label "Entra ID" --expires 2027-09-01
Provisioning token 3f2c6a1e9b8d4c7fa0e1d2c3b4a59687 (scim) created in context 1138, expires 2027-09-01T00:00:00Z
Secret, shown only this once: ox_1138_...
Creates a SCIM token for the context that expires on 1 September 2027; the secret goes into the identity provider's "secret token" field.
createprovisioningtoken -A oxadminmaster -P secret --contexts 1138,1139 --label "Shared account automation" --scope provisioning
Cross-context provisioning token 9b8d4c7fa0e1d2c3b4a596873f2c6a1e (provisioning) created for contexts 1138,1139, expires never
Secret, shown only this once: ox_x_...
Creates a cross-context token for the provisioning API that acts as an administrator of both contexts, for a client that grants shared account permissions between them with a single Authorization: Bearer header.
SEE ALSO
listprovisioningtokens(1), revokeprovisioningtoken(1), detachprovisioningtoken(1), Provisioning over HTTP