Personal access tokens

From MoodleDocs

What are personal access tokens?

New feature
in Moodle 5.3!

A personal access token lets an app or script you use connect to Moodle's new REST API on your behalf. Each token has an expiry date and one or more scopes, which limit what it can do. A token works within your existing permissions in Moodle.

Warning: Anyone who has your token can do anything you can do within its scopes, so keep your tokens private and delete any you no longer use.


How do I create a token?

  1. Go to User menu > Preferences > User account > Personal access tokens.
  2. Click Create token.
  3. Enter a Name and, if you like, a Description, so you can recognise the token later.
  4. Choose an Expiry date: 7 days, 1 month (the default), 2 months, 3 months or 1 year.
  5. Select at least one scope. Each scope shows what it allows.
  6. Click Create token.

You can't change these settings after the token is created.

The Create a personal access token form, with Name, Description, Expiry date and a list of scopes
The Create a personal access token form
Note: Moodle shows your new token only once. Copy it straight away and paste it into your app or script, because you can't see it again after you leave the page.


How do I manage my tokens?

The Personal access tokens page lists all your tokens, with their scopes, status, the date they were created, the date they're valid until, and when and from which IP address they were last used.

The Personal access tokens page, listing a token with its scopes, status, creation and expiry dates, and last access
The Personal access tokens page
  • A warning icon appears next to Valid until when a token expires within 3 days.
  • To stop using an active token, click Revoke. The token stops working straight away and is removed from your list.
  • An expired token shows the status Expired. Click Delete to remove it from your list.

If you need a token again after it expires, create a new one.

Who can create tokens?

Every authenticated user can create personal access tokens by default. Administrators can restrict this by removing the capability moodle/api:createtoken.

See also