All topics

Security, tokens and Alexa

Permissions govern reading, operation and administration. Service tokens are not user passwords.

Available options depend on your version, permissions and hardware. For missing actions, see Security and Diagnostics.

Step by step

  1. Use a role appropriate to the action.
  2. In System > Security create a labeled read-only service token, copy it once and keep it private.
  3. Enable remote access, then follow code-based linking in the Alexa app.

Options explained

Viewer
read. Operator: flow operation/backups read. Designer: also author/publish flows. Admin: devices, integrations, secrets and restoration.
Panel API tokens
read-only; inspect label, usage and revoke. Plaintext is shown once.
Revoke
stops the client using that token; replace when appropriate.
Alexa
requires skill, pairing code and working remote access, not just a token.
Network/console administration
requires host capabilities and permission; not public access.

Troubleshooting

For denied access, check role/session and least necessary privileges. Do not grant wider access instead of investigating faults.

Common problems
Security, tokens and Alexa | HelioPulse | HelioPulse