> ## Documentation Index
> Fetch the complete documentation index at: https://upstash.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# ACL GENTOKEN

> Generate a REST token that can be used as a SETUSER password.

Use `ACL GENTOKEN` to create the credential you need before you can give an ACL user a password.

[`ACL SETUSER`](/docs/redis/commands/server/acl-setuser) does not accept arbitrary passwords with `>password`: the value must come from `GENTOKEN`. Call it with just a username to have a strong password generated for you, or supply your own password to wrap instead. Either way, the reply is a token string that does two things at once: pass it to `SETUSER` as `>token` to set the user's password, and later use it directly as `UPSTASH_REDIS_REST_TOKEN`, or exchange it (or the password it wraps) for a fresh one with [`ACL RESTTOKEN`](/docs/redis/commands/server/acl-resttoken). `GENTOKEN` is an Upstash extension.

## Syntax

```redis theme={"system"}
ACL GENTOKEN <username> [password]
```

## Arguments

| Argument   | Required | Repeatable | Description                                                                                 |
| ---------- | -------- | ---------- | ------------------------------------------------------------------------------------------- |
| `username` | Yes      | No         | ACL user this token will belong to. The user does not need to exist yet.                    |
| `password` | No       | No         | Password to wrap in the token. When omitted, a strong random password is generated instead. |

## Important points

* A supplied `password` is checked for minimum entropy and rejected if too weak.
* This only generates a token; it does not create or modify the user. Pass the result to `ACL SETUSER <username> >token` to actually set it as the user's password.

## Response

The reply reports the result of the operation. Error replies have the same shape in RESP2 and RESP3 and are surfaced as exceptions by the SDKs below.

| Protocol | Reply       |
| -------- | ----------- |
| RESP2    | Bulk string |
| RESP3    | Bulk string |

<Note>
  Client libraries often decode bulk strings, maps, sets, and numeric strings into language-native values. The table describes the Redis wire reply.
</Note>

## Examples

TCP examples use the TLS `REDIS_URL` from the Upstash console. REST examples use `UPSTASH_REDIS_REST_URL` and `UPSTASH_REDIS_REST_TOKEN`.

<AccordionGroup>
  <Accordion title="Redis CLI" icon="terminal">
    ```bash theme={"system"}
    ACL GENTOKEN app
    ```
  </Accordion>

  <Accordion title="@upstash/redis" icon="node-js" iconType="brands">
    <Note>
      This command is not supported yet in `@upstash/redis`.
    </Note>
  </Accordion>

  <Accordion title="upstash_redis" icon="python" iconType="brands">
    <Note>
      This command is not supported yet in `upstash_redis`.
    </Note>
  </Accordion>

  <Accordion title="ioredis" icon="node-js" iconType="brands">
    ```ts theme={"system"}
    import Redis from "ioredis";

    const redis = new Redis(process.env.REDIS_URL!);
    const result = await redis.acl("GENTOKEN", "app");
    console.log(result);
    ```
  </Accordion>

  <Accordion title="node-redis" icon="node-js" iconType="brands">
    ```ts theme={"system"}
    import { createClient } from "redis";

    const client = await createClient({ url: process.env.REDIS_URL })
      .on("error", console.error)
      .connect();
    const result = await client.sendCommand(["ACL", "GENTOKEN", "app"]);
    console.log(result);
    ```
  </Accordion>

  <Accordion title="redis-py" icon="python" iconType="brands">
    ```python theme={"system"}
    import os
    import redis

    client = redis.from_url(os.environ["REDIS_URL"])
    result = client.execute_command("ACL", "GENTOKEN", "app")
    print(result)
    ```
  </Accordion>

  <Accordion title="go-redis" icon="golang" iconType="brands">
    ```go theme={"system"}
    package main

    import (
        "context"
        "fmt"
        "os"

        "github.com/redis/go-redis/v9"
    )

    func main() {
        opts, err := redis.ParseURL(os.Getenv("REDIS_URL"))
        if err != nil {
            panic(err)
        }
        client := redis.NewClient(opts)
        result, err := client.Do(context.Background(), "ACL", "GENTOKEN", "app").Result()
        if err != nil {
            panic(err)
        }
        fmt.Println(result)
    }
    ```
  </Accordion>

  <Accordion title="jedis" icon="java" iconType="brands">
    ```java theme={"system"}
    import java.net.URI;
    import java.nio.charset.StandardCharsets;
    import redis.clients.jedis.Jedis;
    import redis.clients.jedis.commands.ProtocolCommand;

    ProtocolCommand command = () -> "ACL".getBytes(StandardCharsets.UTF_8);
    try (Jedis jedis = new Jedis(new URI(System.getenv("REDIS_URL")))) {
      Object result = jedis.sendCommand(command, "GENTOKEN", "app");
      System.out.println(result);
    }
    ```
  </Accordion>

  <Accordion title="redis-rs" icon="rust" iconType="brands">
    ```rust theme={"system"}
    fn main() -> redis::RedisResult<()> {
        let url = std::env::var("REDIS_URL").expect("REDIS_URL is not set");
        let client = redis::Client::open(url)?;
        let mut connection = client.get_connection()?;

        let mut command = redis::cmd("ACL");
        command.arg("GENTOKEN");
        command.arg("app");
        let result: redis::Value = command.query(&mut connection)?;
        println!("{result:?}");
        Ok(())
    }
    ```
  </Accordion>
</AccordionGroup>


## Related topics

- [ACL RESTTOKEN](/docs/redis/commands/server/acl-resttoken.md)
- [ACL GENPASS](/docs/redis/commands/server/acl-genpass.md)
- [ACL SETUSER](/docs/redis/commands/server/acl-setuser.md)
- [ACL SAVE](/docs/redis/commands/server/acl-save.md)
- [ACL LOAD](/docs/redis/commands/server/acl-load.md)
