---
source_url: https://www.pubnub.com/docs/security/access-control/overview
title: Access Manager
updated_at: 2026-09-30T07:20:08.000Z
---

# Access Manager

> For AI agents: documentation index at https://www.pubnub.com/llms-full.txt

Access Manager controls who can read from or write to PubNub channels and user metadata. Without it, any client that holds your subscribe and publish keys has unrestricted access to every resource on that keyset.

Access Manager is an optional add-on. Enable it per keyset in the [Admin Portal](https://admin.pubnub.com/).

## How it works

Three actors participate in every authorized request:

* **Your server.** Holds the `secretKey`. Validates user identity, determines what the user can access, and calls the PubNub grant API to generate a token. Returns the token to the client.
* **Your client.** Requests a token from your server after login. Sets the token as its `authKey` and sends it with every PubNub API call. Requests a new token before the current one expires.
* **PubNub.** Validates the token on every authenticated request. Rejects requests where the token does not grant the required permission.

The flow for a typical login looks like this:

1. The client sends a login request to your server.
2. Your server validates the user's identity, then calls the PubNub grant API with the `secretKey`.
3. PubNub returns a signed, time-limited token.
4. Your server returns the token to the client.
5. The client sets the token in the SDK and uses it for subsequent API calls.
6. When the token approaches expiry, the client requests a new one from your server.

```mermaid
sequenceDiagram
    participant C as Client
    participant S as Your server
    participant P as PubNub

    C->>S: 1. Login request
    S->>P: 2. Grant token (secretKey)
    P-->>S: 3. Signed token returned
    S-->>C: 4. Token passed to client
    Note over C: 5. SDK sets token as authKey
    C->>P: 6. Authorized API request
    P-->>C: Response
```

The `secretKey` never leaves your server. Client devices never see it.

:::tip No backend server? Use a Function
You don't need to host dedicated infrastructure to grant tokens. A [PubNub Function](https://www.pubnub.com/docs/message-processing/serverless/overview.md) can serve as the token-granting layer. It runs on PubNub's global network with secure access to your secret key and can call `grantToken` in response to a client request, with no server to operate.
:::

## Resources

Access Manager grants permissions for three resource types:

| Resource | Permission flags |
| --- | --- |
| Channel | `read`, `write`, `delete`, `get`, `update`, `manage`, `join` |
| Channel group | `read`, `manage` |
| UUID metadata | `get`, `update`, `delete` |

A token can grant permissions for a specific resource by name, or for a group of resources using RE2 (Regular Expression 2) patterns. Patterns let you write a single grant that covers many channels, for example `^chat\.[A-Za-z0-9]+$` to cover all channels with the prefix `chat.`.

For the mapping of individual PubNub API operations (publish, subscribe, fetch messages, and so on) to specific resource permissions, see [Operations to permissions mapping](https://www.pubnub.com/docs/security/access-control/operations-permissions-mapping.md).

## Tokens

### TTL

Every token has a TTL (Time To Live) in minutes. Every Access Manager token requires a `ttl` in minutes, and there is no default. An Access Manager token's `ttl` ranges from 1 minute to 43,200 minutes (30 days).

A request that uses an expired token fails with `403 Token is expired`. The client must request a new token from your server and set it in the SDK before retrying.

### Authorized UUID

A token can bind to a single User ID (the `authorized_uuid`). When set, PubNub rejects any request that presents the token with a different User ID.

That binding limits what a stolen token can authorize. It doesn't make a stolen token harmless. The User ID a token is bound to is a value the client sends with each request, not a proof of possession, so whoever holds the token can read that User ID and use it to send requests as that user. Treat a bound token as a secret: deliver it to the client only over TLS from an authenticated call to your own server, store it where other code on the device can't read it, keep its TTL short, and revoke it when a session ends or a user is removed. Refer to [Grant, change, and revoke permissions](https://www.pubnub.com/docs/security/access-control/manage-permissions.md) to revoke a token before it expires.

Keep this request-level check separate from authentication. Your server, not this binding, is what decides which User ID a person is allowed to request a token for in the first place.

### Token size

A token stores all permission mappings in its payload. Access Manager `grantToken()` requests over 32 KiB return HTTP 414 (URI Too Long). To avoid this:

* Prefer RE2 patterns over long lists of individual resource names.
* Keep resource names short and consistent.

### Token revocation

Access Manager can revoke a token before it expires. A request that uses a revoked token fails with `403 Revoked Token`. Revocation requires the **Revoke v3 Token** option to be enabled on the keyset in Admin Portal.

Constraints:

* Token revocation is available only when the keyset's token TTL is 43,200 minutes (30 days) or less.
* Each revoke call accepts a single token, so batch revocation isn't supported.
* Token revocation can take up to one minute to take effect, because PubNub caches a token's non-revoked state for that long.
* A revoked token can't be re-enabled.

## Related pages

* [Configure access control](https://www.pubnub.com/docs/security/access-control/configure-access-control.md). Enable Access Manager on a keyset.
* [Permission model](https://www.pubnub.com/docs/security/access-control/permission-model.md). The permission flags a token can grant on each resource type.
* [Initialize a server SDK with a secret key](https://www.pubnub.com/docs/security/access-control/initialize-server-sdk.md). Set up the server-side PubNub instance that grants tokens.
* [Grant, change, and revoke permissions](https://www.pubnub.com/docs/security/access-control/manage-permissions.md). Issue and manage tokens from your server.
* [Initialize a client SDK with an auth key](https://www.pubnub.com/docs/security/access-control/initialize-client-sdk.md). Set the token on the client after it receives one from your server.
* [Operations to permissions mapping](https://www.pubnub.com/docs/security/access-control/operations-permissions-mapping.md). Which permission each PubNub API operation requires.

Last updated at: 2026-09-30T07:20:08.000Z
