# API: How is X-Plex-Token secure?

**URL:** <https://forums.plex.tv/t/api-how-is-x-plex-token-secure/827390>\
**Category:** Dev/API Corner\
**Tags:** other-dev\
**Created:** [January 18, 2023, 6:37pm UTC](https://forums.plex.tv/t/api-how-is-x-plex-token-secure/827390 "2023-01-18T18:37:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alshaw](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/alshaw/32/83356_2.png) [@alshaw](https://forums.plex.tv/u/alshaw)\
**Post date:** [January 18, 2023, 6:37pm UTC](https://forums.plex.tv/t/api-how-is-x-plex-token-secure/827390/1 "2023-01-18T18:37:14Z")

</div>

I know what `X-Plex-Token` is and how to get it; my question is: how is it secure?

Usually, using a token as a query parameter is considered insecure if the token is used more than once. My question is: how is Plex still secure if the API reuses the same token?

---

<div class="post-metadata">

**Author:** ![rickypeepee](https://avatars.discourse-cdn.com/v4/letter/r/f08c70/32.png) [@rickypeepee](https://forums.plex.tv/u/rickypeepee)\
**Post date:** [April 30, 2023, 12:01pm UTC](https://forums.plex.tv/t/api-how-is-x-plex-token-secure/827390/2 "2023-04-30T12:01:39Z")

</div>

It’s only insecure if you expose it to the user. The creation and claiming happen through secured channels and ideally your app should not be storing or passing this in any public way. If you’re using cookies to store it, that’s bad. If you’re passing it with user-facing form data, that’s also bad.

Otherwise the token remains a secret between your app and the API.
