<a id="howto-auth-bearer"></a>

# How to authenticate to the LXD API using bearer tokens

To authenticate to the LXD API using a bearer token, first create an identity of type `bearer`:

CLI

```bash
lxc auth identity create bearer/<name> [[--group <group> ]]
```

The new identity initially has type `Client token bearer (pending)`.
A pending identity cannot authenticate but can be added to groups.

Next, issue a token for the identity (this changes its type to `Client token bearer`):

```bash
lxc auth identity token issue bearer/<name> [--expiry <expiry> ]
```

API

```bash
lxc query --request POST /1.0/auth/identities/bearer --data '{
  "name": "<name>",
  "type": "bearer",
  "groups": [
    "<group>"
  ]
}'
```

Next, issue a token for the identity:

```bash
lxc query --request POST /1.0/auth/identities/bearer/<name>/token --data '{
  "expiry": "<expiry>"
}'
```

UI

Click Permissions in the navigation sidebar, then select Identities from the expanded drop-down list.

Click on the + Create identity button to open the side panel.

Select Bearer token (Main API). Enter a name and optionally a token expiry for the new identity. Select relevant authentication group(s), then click Create identity.

In the modal, click the copy button <span class='guilabel'><svg width='16' height='16' xmlns='http://www.w3.org/2000/svg' aria-hidden='true' style='display:inline-block;vertical-align:text-bottom'><path d='M13.731 10v2.274h2.275v1.5h-2.275v2.232h-1.5v-2.232H10v-1.5h2.231V10h1.5zM11 4.948H5V3.5H3.5v10h5V15h-5A1.5 1.5 0 012 13.5v-10A1.5 1.5 0 013.5 2h1.67a3.001 3.001 0 015.66 0h1.67A1.5 1.5 0 0114 3.5v3.709h-1.5V3.5H11v1.448zM8 1.5a1.5 1.5 0 00-1.493 1.356L6.5 3v.447h3V3a1.5 1.5 0 00-1.356-1.493L8 1.5z' fill='currentColor' fill-rule='nonzero'/></svg></span> to copy the token.

The returned token can be used to authenticate with LXD.
It must be set as a bearer token in the `Authorization` header.

You can verify trust by checking the `auth` field in the response metadata of `GET /1.0`:

```bash
$ curl -k -H "Authorization: Bearer ${TOKEN}" https://<lxd_address>/1.0
{
  ...
  "metadata": {
    "auth":"trusted"
  }
}
```

#### NOTE
The `expiry` field accepts multiple space-separated values of the form `<number><unit>`, such as `1d 3H 5M` (1 day, 3 hours, and 5 minutes).
Case-sensitive units: years (`y`), months (`m`), weeks (`w`), days (`d`), hours (`H`), minutes (`M`), and seconds (`S`).

Note the distinction between months (`m`) and minutes (`M`): for example, `1m` means one month, while `1M` means one minute.

Finally, a token that is no longer needed can be revoked:

CLI

```bash
lxc auth identity token revoke bearer/<name>
```

API

```bash
lxc query --request DELETE /1.0/auth/identities/bearer/<name>/token
```

Revoking the token invalidates it immediately and returns the identity to the pending state.
The identity has type `Client token bearer (pending)` until a new token is issued for it.
The identity remains in its assigned groups, so a newly issued token grants its bearer the same permissions as the revoked one.
