listprovisioningtokens deprecated
PACKAGE: open-xchange-admin
NAME
listprovisioningtokens - lists the provisioning tokens of a context, or the cross-context tokens.
SYNOPSIS
listprovisioningtokens [OPTION]...
DESCRIPTION
This command line tool lists provisioning tokens, expired ones included: identifier, the contexts the token opens, label, scope, the administrator who created the token, when it was created, when it expires and when it was last used successfully. Secrets are never shown. A token that has not been used for a long time is a candidate for revokeprovisioningtoken(1).
Given a context (-c), the tokens bound to that context are listed; cross-context tokens are not among them, even if they open the context. Without a context, the cross-context tokens are listed: all of them for the master administrator, for a reseller administrator those opening only contexts it owns.
Given a context together with --reaching-into, the listing runs the other way round: the cross-context tokens that open that context. A cross-context token is issued by an administrator standing above the contexts, so the context reached into has no part in it and no other way to see it. Each token is shown naming that context and no other - which further contexts it opens is not disclosed here. To end such an access, see detachprovisioningtoken(1).
In a multi-site installation, run the tool on an admin pod of the site the context belongs to: unlike the site-aware provisioning tools, it does not forward the call to another site.
OPTIONS
-c, --contextid contextid : The context identifier. Without, the cross-context tokens are listed.
--reaching-into : Together with -c: list the cross-context tokens that open the context instead of the tokens bound to it.
--csv : Format output to CSV; times are ISO-8601 in UTC, empty where a token does not expire or was never used.
-A, --adminuser admin : Administrator name for authentication. For a context: the context administrator, a reseller administrator owning the context, or the master administrator where MASTER_ACCOUNT_OVERRIDE permits it. For the cross-context tokens: the master administrator, or a reseller administrator where MASTER_ACCOUNT_OVERRIDE permits it; the master administrator sees them with the override off as well. Optional, depending on your configuration.
-P, --adminpass adminPassword : Administrator password for authentication. Optional, depending on your configuration.
-h, --help : Prints a help text.
--environment : Show info about commandline environment.
--nonl : Remove all newlines (\n) from output.
--responsetimeout : The optional response timeout in seconds when reading data from server (default: 0s; infinite).
EXAMPLES
listprovisioningtokens -A contextAdmin -P secret -c 1138
Lists the tokens of the specified context.
listprovisioningtokens -A oxadminmaster -P secret
Lists the cross-context tokens of the installation.
listprovisioningtokens -A contextAdmin -P secret -c 1138 --reaching-into
id contexts label scope created-by created expires never last-used
9b8d4c7fa0e1d2c3b4a596873f2c6a1e 1138 Shared account automation provisioning oxadminmaster 2026-09-15T08:12:00Z never never
Shows what the administrator of context 1138 cannot see otherwise: a cross-context token, issued by the master administrator, that opens this context. The contexts column names 1138 only; the other contexts the token opens are not disclosed.
SEE ALSO
createprovisioningtoken(1), revokeprovisioningtoken(1), detachprovisioningtoken(1), Provisioning over HTTP