Alias tokens
Use your Australian Access Federation (AAF) account to log in to the XNAT website. For an external application, generate an alias token instead of entering your AAF credentials.
An alias token is a temporary, randomised username and password pair associated with your XNAT account. Actions performed with the token are recorded as actions by your account. You can create separate tokens for desktop clients, command line tools and XSync, then revoke each token independently.
Generate an alias token
Section titled “Generate an alias token”-
Log in to XNAT and select your username in the top-right corner to open your profile.

-
Select Manage Alias Tokens, then select Create Alias Token.

-
Find the new token in the table. Check its status and expiry date before using it.

-
Select View to display the token details. Copy the
aliasandsecretvalues to the application that needs them.
Use the token
Section titled “Use the token”When an external application asks for XNAT credentials, use:
aliasas the usernamesecretas the password
Treat both values as credentials. Do not share the secret, include it in screenshots or commit it to a repository. Create a replacement token when the current token approaches the expiry date shown in XNAT.
Revoke a token
Section titled “Revoke a token”Return to Manage Alias Tokens and select Delete beside a token when you no longer need it. Delete it immediately if its secret may have been exposed. Applications using that token will no longer be able to connect.