Personal access tokens
From MoodleDocs
What are personal access tokens?
A personal access token lets an app or script you use connect to Moodle's new REST API on your behalf. Each token has an expiry date and one or more scopes, which limit what it can do. A token works within your existing permissions in Moodle.
| Warning: Anyone who has your token can do anything you can do within its scopes, so keep your tokens private and delete any you no longer use. |
How do I create a token?
- Go to User menu > Preferences > User account > Personal access tokens.
- Click Create token.
- Enter a Name and, if you like, a Description, so you can recognise the token later.
- Choose an Expiry date: 7 days, 1 month (the default), 2 months, 3 months or 1 year.
- Select at least one scope. Each scope shows what it allows.
- Click Create token.
You can't change these settings after the token is created.

Note: Moodle shows your new token only once. Copy it straight away and paste it into your app or script, because you can't see it again after you leave the page.
How do I manage my tokens?
The Personal access tokens page lists all your tokens, with their scopes, status, the date they were created, the date they're valid until, and when and from which IP address they were last used.

- A warning icon appears next to Valid until when a token expires within 3 days.
- To stop using an active token, click Revoke. The token stops working straight away and is removed from your list.
- An expired token shows the status Expired. Click Delete to remove it from your list.
If you need a token again after it expires, create a new one.
Who can create tokens?
Every authenticated user can create personal access tokens by default. Administrators can restrict this by removing the capability moodle/api:createtoken.
See also
- REST API tokens
- OAuth 2 clients
- Security keys: tokens for the existing web services
- Personal access tokens demo (video by Andrew Lyons)