Skip to main content
When interacting with HashiCorp Consul via the CLI, you must authenticate requests using an ACL token. This guide covers four primary ways to supply your token: Environment variables persist across all Consul commands in your current shell, while CLI flags apply only to the specific command where they’re used.

1. Export an Environment Variable

Supply the ACL token once per session. All subsequent Consul commands will automatically pick it up:
Storing tokens as environment variables is convenient, but ensure your shell history is secured to prevent accidental leakage.

2. Export a Token-File Environment Variable

If you prefer keeping tokens out of your shell history, you can point to a file that contains the token:
Validate that the file has restrictive permissions (chmod 600) to protect sensitive data.

3. Use the --token Flag

For one-off commands, specify the token inline. This overrides any environment variable settings:

4. Use the --token-file Flag

Combine the security of a file with the precision of a per-command setting:
The --token-file flag instructs Consul to read the token from the specified path, mirroring the behavior of CONSUL_HTTP_TOKEN_FILE.

Summary

When starting a new shell session, remember to re-export any environment variables. In exam or production scenarios, you may be asked to demonstrate any of these four ACL token injection techniques.

Watch Video