Service tokens
Learn more about service tokens on your Knock account and how they authenticate the Management API, CLI, and MCP server.
A Knock account service token authenticates requests to the Knock Management API, CLI, and MCP server for resources under your Knock account.
Service tokens always start with knock_st_ and are different from your Knock API keys as they authenticate requests to the Knock Management API only.
Generating a new service token
#To use the Management API, CLI, or MCP server, you will first need to generate a service token and use it as a means of authentication.
To generate a service token, from the dashboard go to "Settings," select the "Service tokens" tab, and click the "+ New token" button. Then, provide a name for the token and click "generate" to view and save your newly generated service token.
Revoking a service token
#Service tokens can be revoked under the three-dot menu and by clicking on "Delete token." Deleting a token will immediately revoke its ability to be used against the Knock Management API, CLI, and MCP server.