Help Docs Control Panel Guides The Ultimate Guide to the WHM Control Panel (2025) Security in WHM API Tokens for Remote Access in WHM

API Tokens for Remote Access in WHM

Create and manage WHM API Tokens to allow secure, password-less remote access or to enable API functionality for your server.

WHM supports the use of API Tokens (formerly called Remote Access Keys) to allow you to log in to the server without the use of a password. These tokens can be used for remote access or to enable functionality for a web based API to make changes to your server. For instance, your Liquid Web account in my.liquidweb.com can make changes and updates to your WHM server if you’ve applied a valid API Token. Automated ordering and renewing of SSL certificates is just one example of using your Liquid Web account and an API Token to manage your server.

Creating an API Token

  1. Login to WHM (for more information, see Getting Started with WHM).
  2. Navigate to WHM >> Development >> Manage API Tokens, or type “api” into the search bar at the top left of the screen.

manage api token link

  1. Click Manage API Tokens.
  2. Click Generate Token.

generate token button highlighted

  1. Enter a new name for the API Token that you are creating and select the appropriate permissions required for the account.

name field for api token

  1. Click Save.
  2. WHM will display the API Token (the token was removed from this screenshot, but will be a 32-character, alphanumeric string). You MUST copy the token at this stage as it will no longer be available after you close the screen. Once you’ve copied the token to a safe place, click Yes, I saved my token.

token confirmation button highlighted

  1. You can now apply the token to a remote API for use in managing your WHM server.

Editing Permissions

You can edit permissions for the API Token after it has been created by clicking Edit next to the token that you need to adjust.

edit and revoke buttons highlighted

Revoking Permissions

If you no longer need an API token, you can remove the token by clicking Revoke. This will remove the token from your server and disable remote access using that token.

edit and revoke buttons highlighted

Was this article helpful?