Grafana Cloud

Each Grafana Cloud stack includes provisioned services for metrics, logs, and traces, such as Prometheus, Loki, and Tempo. Clients that send data to or query these services authenticate with a numeric username, which identifies your instance, and a password.

This password is a Grafana Cloud access policy token, not a personal password. You generate and manage the token in the Cloud Portal, on the details page for each service in your stack. If you lose a token or want to rotate one, generate a new token from the same page.

This document explains how to find the username and how to generate a token for the default Cloud data sources. For fine-grained control over scopes, label selectors, or IP ranges, create a custom access policy instead. Refer to Create access policies and tokens.

There are two kinds of token, generated from different places on the same service details page. Which one you need depends on whether you’re reading data from your stack or sending data to it.

Token typeUse it toScopeWhere to generate it
Read tokenQuery your stack’s data, for example as a data source password in GrafanaRead, such as metrics:read and logs:readThe Password field in the data source settings
Write tokenSend data to your stack from a client such as Grafana AlloyWrite, such as metrics:writeThe Generate now link in the send-data section

Before you begin

To manage data source credentials, you need:

  • A Grafana Cloud account and a Grafana Cloud stack.
  • The Admin role in the Cloud Portal. The Generate now link only appears for users with the Admin role. Refer to Grafana Cloud user roles and permissions.

Find your username and connection details

The username and endpoint URL for each service are on the service’s details page in the Cloud Portal.

  1. Sign in to your Grafana Cloud account.
  2. In the Cloud Portal, navigate to your stack.
  3. Select Details for the service you need credentials for, for example Prometheus, Loki, or Tempo.
  4. On the details page, locate the User field and the URL. The username is a numeric instance ID.

Copy these values into your client configuration.

For the Tempo-specific version of these steps, refer to Locate your stack’s URL, user, and password.

Generate a token to query data

Generate a read token when you need to query your stack’s data, for example to configure a data source in Grafana. The Password field on the service details page generates an access policy token with predefined read scopes: metrics:read, logs:read, traces:read, alerts:read, rules:read, and profiles:read. Use this token as the data source password when you query your stack’s data.

  1. Sign in to your Grafana Cloud account.
  2. In the Cloud Portal, navigate to your stack.
  3. Select Details for the service, for example Prometheus, Loki, or Tempo.
  4. On the details page, locate the Password field and select Generate now.
  5. Enter a Token name.
  6. Optionally, set an expiration date for the token in the Expiration field.
  7. Select Create token and copy the token.

Note

The token is only shown once. Copy and save it in a safe place, like a secure note, password app, or other protected location.

To use the token in a data source configuration, refer to Using an access policy token.

Generate a token to send data

Generate a write token when you need to send data to your stack from a client such as Grafana Alloy. Unlike the read token in the Password field, a write token has a write scope and comes from a separate Generate now link in the send-data section of the service details page.

  1. Sign in to your Grafana Cloud account.
  2. In the Cloud Portal, navigate to your stack.
  3. Select Details for the service, for example Prometheus, Loki, or Tempo.
  4. In the section for sending data to Grafana Cloud, locate the API token step and select Generate now. The section title varies by service.
  5. Enter a Token name.
  6. Optionally, set an expiration date for the token in the Expiration field.
  7. Select Create token and copy the token.

Generating a token creates a separate access policy for each service. A write token’s policy has a write scope for its service, for example traces:write for Tempo.

Add the username and token to your client configuration. For example, in a Prometheus remote_write block:

YAML
remote_write:
  - url: <PROMETHEUS_REMOTE_WRITE_ENDPOINT>
    basic_auth:
      username: <INSTANCE_ID>
      password: <CLOUD_ACCESS_POLICY_TOKEN>

Replace INSTANCE_ID with the numeric username from the service details page and CLOUD_ACCESS_POLICY_TOKEN with the token you copied. Restart the client after you update its configuration.

Rotate a token

Rotate tokens periodically as a security best practice, or immediately if a token is lost or compromised.

Generating a new token doesn’t invalidate existing tokens. Old tokens keep working until you delete them or they expire, so you can update your clients before removing the old token.

To rotate a token:

  1. Generate a new token by following the steps in the previous sections.
  2. Update the token in every client that uses it, such as Alloy or Promtail, and in any data source configurations.
  3. Restart the clients.
  4. Delete the old token. In the Cloud Portal, select your organization, then under Security, select Access Policies. Locate the access policy for the old token and select the trash can icon next to the token. There may be a few minutes delay before the deletion applies everywhere.

Troubleshoot credential issues

The Generate now link doesn’t appear. The link only appears for users with the Admin role in the Cloud Portal. Refer to Grafana Cloud user roles and permissions.

Clients stop sending data after you generate a new token. Confirm that you updated the configuration on every client with the new token and restarted the client services. If you deleted the old token, allow a few minutes for the change to apply everywhere.

You can’t find the credentials in Grafana. Don’t look for these credentials in your Grafana instance under Connections > Data sources. Manage them in the Cloud Portal, on the service details page for your stack, as described on this page.

Next steps