The Safenix installation token is shown only once. When you register a server from the dashboard, the control plane generates the token and returns it inside a ready-to-copy installation command.
Safenix retains only a fingerprint of the token. The plaintext value is not stored anywhere on the Safenix side, and no function or user role can display it again.
Where the token is shown
The dashboard keeps the token only in the browser's memory while that registration screen is open. Reloading the page loses the token. Copy the complete installation command when it is displayed.
Where to find it after installation
After a successful installation, the token is stored on the server in:
/etc/safenix/agent.env
Look for the following configuration entry:
SAFENIX_API_TOKEN
The file can be read only by root.
When you need the token again
The token is not needed for the agent's normal daily operation. The agent already reads it from its configuration file.
You need the token only if you run the installation script again on the same machine, for example to change the protected paths or the database mode.
- Read the value of
SAFENIX_API_TOKENfrom/etc/safenix/agent.envasroot. - Pass that value explicitly to the installation command when you run it again.
The installation script never retrieves the token by itself. You must provide it explicitly every time the script is run. Other settings already present in agent.env are preserved automatically, so you do not need to repeat them.
If the token is lost
The installation was never completed
Safenix cannot reissue a token for the same server. Register a new server from the dashboard instead. The new registration receives a new identity and a new token. The old registration, if it is still pending, can be disconnected.
The server is already installed and working
No action is required. The server continues to operate normally, and the token remains in /etc/safenix/agent.env.