Sooner or later somebody asks you for your cPanel password: the developer building an integration, the offsite backup service, the tool that was supposed to create e-mail accounts by itself. Handing over the password is the wrong answer, and the right one is already in the panel.
It is called Manage API Tokens and it is under Security in cPanel. A token is a long string of characters that acts as a key for one program, and that you can delete at any moment without touching anything else.
Why it beats the password
| With the password |
With a token |
| There is only one. Whoever has it has everything, including signing into the panel as you. |
You make one per program. You always know who holds what. |
| To cut one party off you change it, and break every other integration at the same time. |
You delete that one token. The rest carry on and you never notice. |
| Change it for any other reason and the integrations stop without warning, and nobody works out why. |
Change your password whenever you like: tokens do not depend on it. |
| Once you have shared it, you no longer know how many hands it passed through. |
Every token carries the name you gave it. The list tells you what each one is for. |
How to make one, and the first minute rule
| 1 |
Open the tokens page in the security section of cPanel.
|
|
| 2 |
Give it a name that tells the truth. Not «test» and not «token1»: the name of the program or the person who will use it, because in six months that name is the only way you will know which one is safe to delete.
|
|
| 3 |
Look at the options the page offers you before confirming, such as limiting what the token may do or how long it is good for. Whatever is there, use it.
|
|
| 4 |
Copy the token the moment it appears. Put it straight into wherever it will be used, or into a password manager. If you lose it there is no drama: delete that one and make another.
|
|
| 5 |
Hand over the token only, never the account password, and never over an open channel like a group chat.
|
|
|
A token is worth as much as a password. Whoever holds it talks to your account as you. Which means: never inside a code repository (see the warning about the Git folder in Git in cPanel), never in a file inside the public website folder, never pasted into a support ticket or an e-mail. If you suspect one has got out, delete it: one click, and nothing else is affected.
|
What they are actually for
| 1 |
Backups leaving the server. A program that fetches the account copy and takes it elsewhere, without you being there. The advice in making and keeping your own backup still stands.
|
|
| 2 |
Automatic deployment. A system that, when the code changes, tells the server to fetch it and publish it.
|
|
| 3 |
Monitoring. A tool that checks hourly that the account is healthy and shouts when it is not.
|
|
| 4 |
Creating things in bulk. E-mail accounts, subdomains or DNS records, when there are dozens of them rather than two.
|
|
In all these cases the program talks to cPanel at the same address you use to sign into the panel. If the integration hangs with no error at all, the problem is usually the network rather than the token: which ports are open.
Three keys that get confused
| Key |
Which system it belongs to |
| A cPanel API token |
Your hosting account. That is what this article is about, and it is created in cPanel. |
| A WHM API token |
The server, or a reseller account. It is made in a different panel and reaches further. If you are not a reseller, you have none. |
| Your Meu MozOut login |
That is our billing and services area, a different system from cPanel. One password does not work in the other, and they should never be the same. There is an article of its own in this knowledge base setting out which of the two panels you use for what. |
|
Have a clear out once a year. Open the list and delete tokens belonging to programs you stopped using and people who no longer work with you. A forgotten token is an open door nobody watches, and unlike a password it does not expire on its own or draw attention to itself.
|
And while you are in the security section: if your Meu MozOut sign in does not yet ask for a second step, the route is in turning on two-factor authentication.
|
Has a supplier asked you for your cPanel password? Talk to us before you hand it over.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $10.00/mo See plans |