Manage API-token expiry, revocation, rotation and usage metadata
Use the complete API-token lifecycle added by the security release.
Exact navigationAutomatic core protection — no separate staff menu route
What this guide covers
Use the complete API-token lifecycle added by the security release. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.
Exact step-by-step process
- Use the supported Britixo CRM release or workflow that produces this security control.
- Verify the expected protection through an authorised test.
- Record the result in the deployment or security audit evidence.
Fields, choices and supported possibilities
- Expiry
- Revoked state
- Rotation relationship
- Last-used metadata
- Usage metadata
Code-backed validations and workflow rules
- Set and monitor token expiry.
- Revoke a compromised or retired token.
- Rotate by issuing a new token and retiring the prior one according to the authorised overlap policy.
- Review last-used and other usage metadata for attribution.
Expected result and verification
- The protection is active without weakening another security control.
Security, audit and troubleshooting checks
- Use the exact authorised account, role and record before saving or sending.
- Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
- Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
- Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.
