# APM (observability): what rights of secret token?

**URL:** <https://discuss.elastic.co/t/apm-observability-what-rights-of-secret-token/361094>\
**Category:** APM\
**Tags:** server, php\
**Created:** [June 9, 2024, 9:55am UTC](https://discuss.elastic.co/t/apm-observability-what-rights-of-secret-token/361094 "2024-06-09T09:55:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![NominaSumpta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nominasumpta/32/52412_2.png) [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Post date:** [June 9, 2024, 9:55am UTC](https://discuss.elastic.co/t/apm-observability-what-rights-of-secret-token/361094/1 "2024-06-09T09:55:07Z")

</div>

What rights does the secret token have? Or, put differently, what risk exists when it is leaked?

APM supports [secret tokens](https://www.elastic.co/guide/en/observability/current/apm-secret-token.html#apm-create-secret-token).

I specify one in the server config (`apm-server.auth.secret_token`), then in the agent (e.g . `elastic_apm.secret_token` for the PHP agent).

Although - at least - the PHP agent masquerades it:

```auto
root@http-tst01:/etc/php# php -i | grep elastic_apm.secret_token
elastic_apm.secret_token => ***=>*** => ***
elastic_apm.secret_token => ***=>***

```

... the documentation does not clarify what rights it actually has. Is it push-only? Can it read data? Is it scoped? Etc.
