---
title: "Manage credentials for Cloud data sources | Grafana Cloud documentation"
description: "Find the username and generate or rotate the API token for default Grafana Cloud data sources like Prometheus, Loki, and Tempo."
---

> For a curated documentation index, see [llms.txt](/llms.txt). For the complete documentation index, see [llms-full.txt](/llms-full.txt).

[Documentation](/docs/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Grafana Cloud](/docs/grafana-cloud/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Platform](/docs/grafana-cloud/platform/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Security and account management](/docs/grafana-cloud/platform/security-and-account-management/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Security and access](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Authentication and authorization](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) [Grafana Cloud Access Policies](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/)![breadcrumb arrow](/static/assets/img/icons/grafana-icon-breadcrumb-arrow-gray.svg) Manage data source credentials

Grafana Cloud

Each Grafana Cloud stack includes provisioned services for metrics, logs, and traces, such as Prometheus, Loki, and Tempo. Clients that send data to or query these services authenticate with a numeric username, which identifies your instance, and a password.

This password is a Grafana Cloud access policy token, not a personal password. You generate and manage the token in the Cloud Portal, on the details page for each service in your stack. If you lose a token or want to rotate one, generate a new token from the same page.

This document explains how to find the username and how to generate a token for the default Cloud data sources. For fine-grained control over scopes, label selectors, or IP ranges, create a custom access policy instead. Refer to [Create access policies and tokens](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/create-access-policies/).

There are two kinds of token, generated from different places on the same service details page. Which one you need depends on whether you’re reading data from your stack or sending data to it.

Expand table

| Token type  | Use it to                                                                 | Scope                                        | Where to generate it                               |
|-------------|---------------------------------------------------------------------------|----------------------------------------------|----------------------------------------------------|
| Read token  | Query your stack’s data, for example as a data source password in Grafana | Read, such as `metrics:read` and `logs:read` | The **Password** field in the data source settings |
| Write token | Send data to your stack from a client such as Grafana Alloy               | Write, such as `metrics:write`               | The **Generate now** link in the send-data section |

## Before you begin

To manage data source credentials, you need:

- A Grafana Cloud account and a Grafana Cloud stack.
- The Admin role in the Cloud Portal. The **Generate now** link only appears for users with the Admin role. Refer to [Grafana Cloud user roles and permissions](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/cloud-roles/).

## Find your username and connection details

The username and endpoint URL for each service are on the service’s details page in the Cloud Portal.

1. Sign in to your Grafana Cloud account.
2. In the Cloud Portal, navigate to your stack.
3. Select **Details** for the service you need credentials for, for example Prometheus, Loki, or Tempo.
4. On the details page, locate the **User** field and the URL. The username is a numeric instance ID.

Copy these values into your client configuration.

For the Tempo-specific version of these steps, refer to [Locate your stack’s URL, user, and password](/docs/grafana-cloud/observe-and-act/send-data/traces/set-up/locate-url-user-password/).

## Generate a token to query data

Generate a read token when you need to query your stack’s data, for example to configure a data source in Grafana. The **Password** field on the service details page generates an access policy token with predefined read scopes: `metrics:read`, `logs:read`, `traces:read`, `alerts:read`, `rules:read`, and `profiles:read`. Use this token as the data source password when you query your stack’s data.

1. Sign in to your Grafana Cloud account.
2. In the Cloud Portal, navigate to your stack.
3. Select **Details** for the service, for example Prometheus, Loki, or Tempo.
4. On the details page, locate the **Password** field and select **Generate now**.
5. Enter a **Token name**.
6. Optionally, set an expiration date for the token in the **Expiration** field.
7. Select **Create token** and copy the token.

> Note
> 
> The token is only shown once. Copy and save it in a safe place, like a secure note, password app, or other protected location.

To use the token in a data source configuration, refer to [Using an access policy token](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/using-an-access-policy-token/).

## Generate a token to send data

Generate a write token when you need to send data to your stack from a client such as Grafana Alloy. Unlike the read token in the **Password** field, a write token has a write scope and comes from a separate **Generate now** link in the send-data section of the service details page.

1. Sign in to your Grafana Cloud account.
2. In the Cloud Portal, navigate to your stack.
3. Select **Details** for the service, for example Prometheus, Loki, or Tempo.
4. In the section for sending data to Grafana Cloud, locate the API token step and select **Generate now**. The section title varies by service.
5. Enter a **Token name**.
6. Optionally, set an expiration date for the token in the **Expiration** field.
7. Select **Create token** and copy the token.

Generating a token creates a separate access policy for each service. A write token’s policy has a write scope for its service, for example `traces:write` for Tempo.

Add the username and token to your client configuration. For example, in a Prometheus `remote_write` block:

YAML ![Copy code to clipboard](/media/images/icons/icon-copy-small-2.svg) Copy

```yaml
remote_write:
  - url: <PROMETHEUS_REMOTE_WRITE_ENDPOINT>
    basic_auth:
      username: <INSTANCE_ID>
      password: <CLOUD_ACCESS_POLICY_TOKEN>
```

Replace INSTANCE\_ID with the numeric username from the service details page and CLOUD\_ACCESS\_POLICY\_TOKEN with the token you copied. Restart the client after you update its configuration.

## Rotate a token

Rotate tokens periodically as a security best practice, or immediately if a token is lost or compromised.

Generating a new token doesn’t invalidate existing tokens. Old tokens keep working until you delete them or they expire, so you can update your clients before removing the old token.

To rotate a token:

1. Generate a new token by following the steps in the previous sections.
2. Update the token in every client that uses it, such as Alloy or Promtail, and in any data source configurations.
3. Restart the clients.
4. Delete the old token. In the Cloud Portal, select your organization, then under **Security**, select **Access Policies**. Locate the access policy for the old token and select the trash can icon next to the token. There may be a few minutes delay before the deletion applies everywhere.

## Troubleshoot credential issues

**The Generate now link doesn’t appear.** The link only appears for users with the Admin role in the Cloud Portal. Refer to [Grafana Cloud user roles and permissions](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/cloud-roles/).

**Clients stop sending data after you generate a new token.** Confirm that you updated the configuration on every client with the new token and restarted the client services. If you deleted the old token, allow a few minutes for the change to apply everywhere.

**You can’t find the credentials in Grafana.** Don’t look for these credentials in your Grafana instance under **Connections** &gt; **Data sources**. Manage them in the Cloud Portal, on the service details page for your stack, as described on this page.

## Next steps

- [Grafana Cloud Access Policies](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/) explains scopes, realms, and tokens.
- [Create access policies and tokens](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/create-access-policies/) covers custom access policies with specific scopes, label selectors, and IP ranges.
- [Using an access policy token](/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/using-an-access-policy-token/) shows how to use a token in a data source or with the Cloud API.
- To send data to your stack, refer to the guides for [metrics](/docs/grafana-cloud/observe-and-act/send-data/metrics/), [logs](/docs/grafana-cloud/observe-and-act/send-data/logs/), and [traces](/docs/grafana-cloud/observe-and-act/send-data/traces/).
