API Tokens & Devices
API Tokens & Devices
API Tokens & Devices, found in your user menu, shows everything that can act as you in the system outside of your normal sign-in including any API tokens that belong to your account. If you never use the mobile app or connect other tools, this panel will simply be empty — there is nothing you need to do here.
Signed-in devices
Every device signed in to your account is listed with its name, when it was last used, and from where. If a device looks unfamiliar, or you lose your phone, click Sign out next to it — that device is disconnected immediately and would need your full sign-in (including any verification code) to come back. Sign out all disconnects every device at once. You can also rename a device so the list stays recognizable, for example "Work iPhone" instead of the model name.
Your API tokens
An API token is a stand-in for your password that you can give to a tool that works with DocMgt on your behalf — a script, a Power Automate flow, or an AI assistant connected through the MCP server. The tool uses the token to sign in as you and can do exactly what you can do, nothing more. Tokens created for you by an administrator also appear here, marked accordingly. You can rename any of your tokens and revoke any of them; revoking is immediate, and whatever was using that token stops working until it is given a new one.
Creating a token
If your site allows it, click New Token, give the token a name that says where you will use it, and choose when it should expire — your site may limit how long your tokens can last. Because a token lets anything holding it act as you, DocMgt confirms it is really you first: enter your password, and if your site uses multi-factor authentication, also enter a verification code sent by email or text message or taken from your authenticator app. If you sign in only through your company's single sign-on, you may be asked to sign out and back in first, then create the token within a few minutes.
Copy the token right away
The new token is shown one time only. Copy it immediately and paste it into the tool that needs it — after the dialog is closed the token can never be shown again. If you lose it, revoke it and create a new one. Treat a token like a password: never send it in email or chat, and never share it with anyone.
TIPS
- Check this panel occasionally — if a device or token you don't recognize appears, sign it out or revoke it and tell your administrator.
- Sign out a lost phone immediately; the app on it stops working on the spot.
- Give tokens names you will recognize later, one token per tool.
- When a tool stops working and its token has expired, create a new token and update the tool — expired tokens cannot be extended.
NOTE: Anything holding one of your tokens, and any signed-in device, can act as you in DocMgt. Keep tokens secret, and revoke anything you no longer use.