# API Token Mgmt

**URL:** <https://forums.plex.tv/t/api-token-mgmt/941018>\
**Category:** Feature Suggestions\
**Tags:** pms-api\
**Created:** [July 25, 2026, 2:18pm UTC](https://forums.plex.tv/t/api-token-mgmt/941018 "2026-07-25T14:18:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![PlexTv](https://avatars.discourse-cdn.com/v4/letter/p/bbce88/32.png) [@PlexTv](https://forums.plex.tv/u/PlexTv)\
**Post date:** [July 25, 2026, 2:18pm UTC](https://forums.plex.tv/t/api-token-mgmt/941018/1 "2026-07-25T14:18:33Z")

</div>

Implement a dedicated, secure mechanism to generate, rotate, and revoke access tokens used by AI agents (such as Hermes Agent). Tokens are currently extracted via XML views, creating a security risk when passed through third-party API relays or model providers. Native generation paired with lifecycle controls like instant rotation and revocation will prevent credential leaks and ensure secure agent access.

I realised the token generated via the XML views is still valid even after revoking the corresponding sessions in the Plex Web UI. I don’t understand why would this happended.

Then I tried the method described in [Authenticating with Plex](https://forums.plex.tv/t/authenticating-with-plex/609370) , it works but this could be encapsulate as a user-friendly Web UI interaction.

Fine-grained access token will be more helpful. I may create a read-only token or a token for a specific scope of library.

---

<div class="post-metadata">

**Author:** ![dane22](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dane22/32/4389_2.png) [@dane22](https://forums.plex.tv/u/dane22)\
**Post date:** [July 25, 2026, 4:15pm UTC](https://forums.plex.tv/t/api-token-mgmt/941018/2 "2026-07-25T16:15:28Z")

</div>

> [@PlexTv](#):
>
> I may create a read-only token or a token for a specific scope of library.

Why not create a dedicated user for your AI, and share what you want to that user

This way, it’ll be R/O
