Skip to main content

Manage token brokers

Learn how to manage token brokers used for the browser extension in SaaS.

To access Token broker registrations, you require the Snow Atlas System administrator and Administrator roles.

Edit token broker registrations

You can edit the name and description of token broker registrations.

To change signing certificates, see Upload new signing certificates. To register a new secret key, see Register new secret keys.

  1. In Snow Atlas, go to Settings, and select SaaS settings.

  2. On the Token broker registrations page, select the checkbox for the registration that you want to edit.

  3. On the Actions menu, select Edit.

  4. In Edit, edit the applicable fields.

  5. Select Save.

Upload new signing certificates

You can upload a second signing certificate for a token broker registration if you need to do a rollover of certificates and want to avoid disruption to the token broker service. Both certificates are valid until you delete the previous one from the registration.

  1. In Snow Atlas, go to Settings, and select SaaS settings.

  2. On the Token broker registrations page, select the checkbox for the registration that you want to edit.

  3. On the Actions menu, select Edit.

  4. In Certificate 2, upload your new signing certificate.

    caution

    You are recommended to keep Certificate 1 until you have replaced the signing certificate in the token broker proxy. If you delete the first certificate at the same time as uploading a second one, there will be a disruption in the connection between the browser extension and Snow Atlas, and data may be lost.

  5. Select Save.

    The new certificate is registered.

  6. Replace the certificate in your token broker proxy with the new one, and restart the service.

  7. Go back to the Token broker registrations page in Snow Atlas, and select the checkbox for the registration for which you want to delete the previous certificate.

  8. On the Actions menu, select Edit.

  9. In Certificate 1, select Delete.

  10. Select Save.

    The deleted certificate is no longer valid.

Register new secret keys

You can register a new secret key if needed. The old key becomes invalid immediately, and the the connection between the browser extension and Snow Atlas is broken, until you have added the new key in the token broker proxy.

  1. In Snow Atlas, go to Settings, and select SaaS settings.

  2. On the Token broker registrations page, select the checkbox for the registration for which you want to register a new secret key.

  3. On the Actions menu, select Register new secret key.

  4. In Register new secret key, select Register secret key.

    The new secret key is registered and shown.

  5. Select Copy. You must copy the value before you can continue.

    caution

    The Secret key is only displayed once and cannot be accessed again. Copy and save it. If you lose it, you must register a new one.

  6. Select Close.

  7. Replace the secret key in your token broker proxy with the copied value, and restart the service.

Delete token broker registrations

You can delete a token broker registration. The credentials become invalid immediately and the connection between the browser extension and Snow Atlas is broken.

  1. In Snow Atlas, go to Settings, and select SaaS settings.

  2. On the Token broker registrations page, select the checkboxes for the registrations that you want to delete.

  3. In Delete token broker registrations menu, select Delete.

  4. Remove the token broker proxy from your cluster.