📣
TiDB Cloud Premium is now in public preview. Unlimited growth, instant elasticity, advanced security for enterprise workloads. Try it out →

ti fs delete-file-system-token



Permanently revokes a file system token. The token stops authenticating after the change propagates and no longer appears in list results. An owner token can revoke either token kind in the same file system; a scoped token cannot use this command.

Syntax

ti fs delete-file-system-token --token-id <string> [--file-system-id <string>] [--fs-token <string>] [--dry-run] [--help] [--version]

Options

  • --file-system-id <string>: Specify the file system that owns the token. Required when using TiDB Cloud API credentials; optional when an owner token supplies the ID.
  • --token-id <string>: Specify the immutable token ID returned by the list command. This option is required.
  • --fs-token <string>: Authorize the request with a file system owner token. If omitted, the command uses the TI_FS_TOKEN environment variable. If neither is provided, the command requires TiDB Cloud API credentials and --file-system-id. It does not automatically use a locally stored owner token.
  • --dry-run: Validate credentials, identifiers, and known local mount conflicts without revoking the token.
  • --help: Display help information.
  • --version: Display version information.

For options shared by all commands, see Global options.

Examples

  • Revoke an old token after validating its replacement:

    # Revocation is permanent; use disable first when you need a reversible rollout. ti fs delete-file-system-token \ --file-system-id "<file-system-id>" \ --token-id "<old-token-id>"
  • Revoke a token by using an owner token:

    # The owner token identifies the file system; use the immutable ID of the token being revoked. TI_FS_TOKEN="<owner-fs-token>" ti fs delete-file-system-token \ --token-id "<old-token-id>"

Was this page helpful?