> ## Documentation Index
> Fetch the complete documentation index at: https://3to1go.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Edge credentials

> Authorize Edges to upload to Central, share a credential between machines, and revoke access.

Edges authenticate to Central with a signed credential that Central mints. Central keeps a record of each credential but never stores the raw token.

## Mint a credential

<Steps>
  <Step title="Open the dialog">
    In Central, click **Mint Edge Credential**.
  </Step>

  <Step title="Choose options">
    * **TTL Days**: how long the credential is valid, from 1 to 3650 days (default 365).
    * **Shared credential**: leave off for one Edge. See [Shared credentials](#shared-credentials).
  </Step>

  <Step title="Mint and copy">
    Click **Mint Credential**, then **Copy**.
  </Step>

  <Step title="Paste it into Edge">
    In Edge, open **Edit Edge Settings** and paste it into **Edge Credential**, then save.
  </Step>
</Steps>

<Warning>
  The credential is shown **once**. Paste it into Edge before closing the dialog. If you lose it, mint another.
</Warning>

## How binding works

A normal credential is **single-instance**: it binds to the first Edge installation that reports in with it. After that, Central rejects the same credential from any other installation.

## Shared credentials

To use one credential on several machines, turn on **Shared credential** and set **Shared Instance Limit** to the number of Edge installations allowed to use it (2 to 10000).

Each machine still gets its own instance ID, so their snapshots stay separate on Central.

## Revoke a credential

Revoke a credential from Central's snapshot view with **Revoke Token** on the Edge instance. Revoking stops future uploads with that credential but **keeps** the snapshots already stored.

<Note>
  Central can only revoke a credential after at least one Edge has reported in with it. A credential that was never used simply expires at the end of its TTL.
</Note>

If the credential is shared, revoking it stops **every** Edge instance that uses it.

Revocation also prevents those Edges from downloading snapshots for restore. Downloads through Central's signed-in web UI remain available.

## Replace a credential

Revoke the instance's existing credential before minting and saving its replacement in Edge. Central rejects a different credential while the instance is still bound to the old one. The replacement binds when Edge next initiates an upload; simply saving it in Edge does not bind it for restore.

## Delete an Edge instance

**Delete Instance** permanently deletes **all snapshots** for that Edge instance and removes it from Central. It can't be undone, so only use it for machines you've retired and no longer need backups from.

If Central can't find any backup files for an instance, it offers to remove the stale entry from the list instead.

Deleting an instance does not revoke its credential. Stop the retired Edge or revoke its credential first if it must no longer upload.
