Documentation for automated readers
A curated documentation index is available at: https://grafana.com/llms.txt
A complete documentation index is available at: https://grafana.com/llms-full.txt
These indexes can help with page discovery before fetching individual documents.
This page is also available in Markdown, which may be easier for automated readers and AI tools to parse than HTML. The Markdown version is available at https://grafana.com/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/manage-cloud-data-source-credentials.md, or by sending Accept: text/markdown to https://grafana.com/docs/grafana-cloud/platform/security-and-account-management/security-and-access/authentication-and-permissions/access-policies/manage-cloud-data-source-credentials/. For broader documentation discovery, the curated index is available at https://grafana.com/llms.txt and the complete index is available at https://grafana.com/llms-full.txt.
Each Grafana Cloud stack includes provisioned services for metrics, logs, and traces, such as Prometheus, Loki, and Tempo. Clients that send data to or query these services authenticate with a numeric username, which identifies your instance, and a password.
This password is a Grafana Cloud access policy token, not a personal password. You generate and manage the token in the Cloud Portal, on the details page for each service in your stack. If you lose a token or want to rotate one, generate a new token from the same page.
This document explains how to find the username and how to generate a token for the default Cloud data sources. For fine-grained control over scopes, label selectors, or IP ranges, create a custom access policy instead. Refer to Create access policies and tokens.
There are two kinds of token, generated from different places on the same service details page. Which one you need depends on whether you’re reading data from your stack or sending data to it.
| Token type | Use it to | Scope | Where to generate it |
|---|---|---|---|
| Read token | Query your stack’s data, for example as a data source password in Grafana | Read, such as metrics:read and logs:read | The Password field in the data source settings |
| Write token | Send data to your stack from a client such as Grafana Alloy | Write, such as metrics:write | The Generate now link in the send-data section |
Before you begin
To manage data source credentials, you need:
- A Grafana Cloud account and a Grafana Cloud stack.
- The Admin role in the Cloud Portal. The Generate now link only appears for users with the Admin role. Refer to Grafana Cloud user roles and permissions.
Find your username and connection details
The username and endpoint URL for each service are on the service’s details page in the Cloud Portal.
- Sign in to your Grafana Cloud account.
- In the Cloud Portal, navigate to your stack.
- Select Details for the service you need credentials for, for example Prometheus, Loki, or Tempo.
- On the details page, locate the User field and the URL. The username is a numeric instance ID.
Copy these values into your client configuration.
For the Tempo-specific version of these steps, refer to Locate your stack’s URL, user, and password.
Generate a token to query data
Generate a read token when you need to query your stack’s data, for example to configure a data source in Grafana.
The Password field on the service details page generates an access policy token with predefined read scopes: metrics:read, logs:read, traces:read, alerts:read, rules:read, and profiles:read.
Use this token as the data source password when you query your stack’s data.
- Sign in to your Grafana Cloud account.
- In the Cloud Portal, navigate to your stack.
- Select Details for the service, for example Prometheus, Loki, or Tempo.
- On the details page, locate the Password field and select Generate now.
- Enter a Token name.
- Optionally, set an expiration date for the token in the Expiration field.
- Select Create token and copy the token.
Note
The token is only shown once. Copy and save it in a safe place, like a secure note, password app, or other protected location.
To use the token in a data source configuration, refer to Using an access policy token.
Generate a token to send data
Generate a write token when you need to send data to your stack from a client such as Grafana Alloy. Unlike the read token in the Password field, a write token has a write scope and comes from a separate Generate now link in the send-data section of the service details page.
- Sign in to your Grafana Cloud account.
- In the Cloud Portal, navigate to your stack.
- Select Details for the service, for example Prometheus, Loki, or Tempo.
- In the section for sending data to Grafana Cloud, locate the API token step and select Generate now. The section title varies by service.
- Enter a Token name.
- Optionally, set an expiration date for the token in the Expiration field.
- Select Create token and copy the token.
Generating a token creates a separate access policy for each service.
A write token’s policy has a write scope for its service, for example traces:write for Tempo.
Add the username and token to your client configuration.
For example, in a Prometheus remote_write block:
remote_write:
- url: <PROMETHEUS_REMOTE_WRITE_ENDPOINT>
basic_auth:
username: <INSTANCE_ID>
password: <CLOUD_ACCESS_POLICY_TOKEN>Replace INSTANCE_ID with the numeric username from the service details page and CLOUD_ACCESS_POLICY_TOKEN with the token you copied. Restart the client after you update its configuration.
Rotate a token
Rotate tokens periodically as a security best practice, or immediately if a token is lost or compromised.
Generating a new token doesn’t invalidate existing tokens. Old tokens keep working until you delete them or they expire, so you can update your clients before removing the old token.
To rotate a token:
- Generate a new token by following the steps in the previous sections.
- Update the token in every client that uses it, such as Alloy or Promtail, and in any data source configurations.
- Restart the clients.
- Delete the old token. In the Cloud Portal, select your organization, then under Security, select Access Policies. Locate the access policy for the old token and select the trash can icon next to the token. There may be a few minutes delay before the deletion applies everywhere.
Troubleshoot credential issues
The Generate now link doesn’t appear. The link only appears for users with the Admin role in the Cloud Portal. Refer to Grafana Cloud user roles and permissions.
Clients stop sending data after you generate a new token. Confirm that you updated the configuration on every client with the new token and restarted the client services. If you deleted the old token, allow a few minutes for the change to apply everywhere.
You can’t find the credentials in Grafana. Don’t look for these credentials in your Grafana instance under Connections > Data sources. Manage them in the Cloud Portal, on the service details page for your stack, as described on this page.
Next steps
- Grafana Cloud Access Policies explains scopes, realms, and tokens.
- Create access policies and tokens covers custom access policies with specific scopes, label selectors, and IP ranges.
- Using an access policy token shows how to use a token in a data source or with the Cloud API.
- To send data to your stack, refer to the guides for metrics, logs, and traces.
Was this page helpful?
Related resources from Grafana Labs


