Credentials
A credential lets a customer's install talk to Chandler over the internet. This page explains how to create one, hand it over safely, and replace it.
A credential is not the license. The license is what allows the customer to use the product; a credential is only the key one install uses to reach Chandler online. See Licenses and credentials: what's the difference.
You need the License admin permission to create, rotate or revoke credentials.
What is a credential
A credential is a long secret code that belongs to one license. The customer's install uses it to:
- check that its license is still in good standing
- fetch a renewed license file by itself
- download updates it is covered for
It looks like this, but much longer: chn_trawler_…. The middle part is
different for every credential. Engineering may also call it a key or a
token.
A credential works only for its own product. A Trawler credential can never fetch anything for Portolan or Driftnet.
Installs without internet don't need a credential. Send them the license file instead. See Offline installs.
A license can have more than one credential. For example, one for each customer site. Each one can be rotated or revoked on its own.
Creating a credential
- Open the license page.
- Click Create credential.
- Chandler may ask you to sign in again. This is normal for important actions. See Asked to sign in again.
- Read the confirmation, then click Create credential.
- Chandler shows the secret code once. Follow Saving the secret now.
The new credential then appears on the license page, marked Active. The audit log records that you created it, but never the code itself.
If you see This credential was already created, the page was sent twice. Chandler made only one credential. If nobody saved its secret, use Rotate to get a new one.
Saving the secret
Chandler shows the secret code only once. It doesn't keep a copy it could show you again, so save it before you leave the page.
- Click Copy to copy the code. If there is no Copy button, select the code and copy it yourself.
- Paste it somewhere safe that the customer can reach. Use the secure sharing tool your team agreed on, such as a password manager.
- Tick the box, then click I have saved it. Chandler hides the code.
Keep it safe:
- Never paste the code into ordinary email, a chat message or a ticket.
- Never put it in a screenshot.
- If you think someone else has seen it, rotate it.
Chandler never writes the code into its logs or its audit log. The audit log only records that a credential was created, and by whom.
Rotating a credential
Rotating replaces a credential with a new one. Do it when:
- the secret code was lost
- someone who shouldn't have it may have seen it
- the customer asks for a new one
Steps:
- Open the license page.
- Next to the credential, click Rotate.
- Chandler may ask you to sign in again.
- Read the confirmation, then click Rotate.
- Save the new secret code. See Saving the secret.
The old code stops working straight away. The customer's install can't reach Chandler until someone enters the new code. Agree a time with the customer first if you can.
The install keeps running while it waits for the new code. Only its online checks and downloads stop.
Revoking a credential
Revoke a credential when it should stop working and nothing will replace it. For example, when the customer closes one of their sites.
- Open the license page.
- Next to the credential, click Revoke credential.
- Read the confirmation, then click Revoke credential.
The credential stops working straight away, and this can't be undone. It stays on the license page, marked Revoked, with the date. The license itself doesn't change. Installed copies keep running until the end date.
To give the customer access again later, create a new credential.
If a customer lost their credential
Chandler can't show a secret code again. Nobody at ExactNet can read it, because Chandler never stored it.
- Rotate the credential. The lost code stops working.
- Send the customer the new code, safely.
- Ask them to enter the new code in their install.