# ACL GENTOKEN

> Generate a REST token that can be used as a SETUSER password.

Use `ACL GENTOKEN` to create the credential you need before you can give an ACL user a password.

[`ACL SETUSER`](/redis/commands/server/acl-setuser) does not accept arbitrary passwords with `>password`: the value must come from `GENTOKEN`. Call it with just a username to have a strong password generated for you, or supply your own password to wrap instead. Either way, the reply is a token string that does two things at once: pass it to `SETUSER` as `>token` to set the user's password, and later use it directly as `UPSTASH_REDIS_REST_TOKEN`, or exchange it (or the password it wraps) for a fresh one with [`ACL RESTTOKEN`](/redis/commands/server/acl-resttoken). `GENTOKEN` is an Upstash extension.

## Syntax

```redis
ACL GENTOKEN <username> [password]
```

## Arguments

| Argument | Required | Repeatable | Description |
| --- | --- | --- | --- |
| `username` | Yes | No | ACL user this token will belong to. The user does not need to exist yet. |
| `password` | No | No | Password to wrap in the token. When omitted, a strong random password is generated instead. |

## Important points

- A supplied `password` is checked for minimum entropy and rejected if too weak.
- This only generates a token; it does not create or modify the user. Pass the result to `ACL SETUSER <username> >token` to actually set it as the user's password.

## Response

The reply reports the result of the operation. Error replies have the same shape in RESP2 and RESP3 and are surfaced as exceptions by the SDKs below.

| Protocol | Reply |
| --- | --- |
| RESP2 | Bulk string |
| RESP3 | Bulk string |

<Note>
  Client libraries often decode bulk strings, maps, sets, and numeric strings into language-native values. The table describes the Redis wire reply.
</Note>

## Examples

TCP examples use the TLS `REDIS_URL` from the Upstash console. REST examples use `UPSTASH_REDIS_REST_URL` and `UPSTASH_REDIS_REST_TOKEN`.

<AccordionGroup>

<Accordion title="Redis CLI" icon="terminal">

```bash
ACL GENTOKEN app
```

</Accordion>

<Accordion title="@upstash/redis" icon="node-js" iconType="brands">

<Note>
  This command is not supported yet in `@upstash/redis`.
</Note>

</Accordion>

<Accordion title="upstash_redis" icon="python" iconType="brands">

<Note>
  This command is not supported yet in `upstash_redis`.
</Note>

</Accordion>

<Accordion title="ioredis" icon="node-js" iconType="brands">

```ts
import Redis from "ioredis";

const redis = new Redis(process.env.REDIS_URL!);
const result = await redis.acl("GENTOKEN", "app");
console.log(result);
```

</Accordion>

<Accordion title="node-redis" icon="node-js" iconType="brands">

```ts
import { createClient } from "redis";

const client = await createClient({ url: process.env.REDIS_URL })
  .on("error", console.error)
  .connect();
const result = await client.sendCommand(["ACL", "GENTOKEN", "app"]);
console.log(result);
```

</Accordion>

<Accordion title="redis-py" icon="python" iconType="brands">

```python
import os
import redis

client = redis.from_url(os.environ["REDIS_URL"])
result = client.execute_command("ACL", "GENTOKEN", "app")
print(result)
```

</Accordion>

<Accordion title="go-redis" icon="golang" iconType="brands">

```go
package main

import (
    "context"
    "fmt"
    "os"

    "github.com/redis/go-redis/v9"
)

func main() {
    opts, err := redis.ParseURL(os.Getenv("REDIS_URL"))
    if err != nil {
        panic(err)
    }
    client := redis.NewClient(opts)
    result, err := client.Do(context.Background(), "ACL", "GENTOKEN", "app").Result()
    if err != nil {
        panic(err)
    }
    fmt.Println(result)
}
```

</Accordion>

<Accordion title="jedis" icon="java" iconType="brands">

```java
import java.net.URI;
import java.nio.charset.StandardCharsets;
import redis.clients.jedis.Jedis;
import redis.clients.jedis.commands.ProtocolCommand;

ProtocolCommand command = () -> "ACL".getBytes(StandardCharsets.UTF_8);
try (Jedis jedis = new Jedis(new URI(System.getenv("REDIS_URL")))) {
  Object result = jedis.sendCommand(command, "GENTOKEN", "app");
  System.out.println(result);
}
```

</Accordion>

<Accordion title="redis-rs" icon="rust" iconType="brands">

```rust
fn main() -> redis::RedisResult<()> {
    let url = std::env::var("REDIS_URL").expect("REDIS_URL is not set");
    let client = redis::Client::open(url)?;
    let mut connection = client.get_connection()?;

    let mut command = redis::cmd("ACL");
    command.arg("GENTOKEN");
    command.arg("app");
    let result: redis::Value = command.query(&mut connection)?;
    println!("{result:?}");
    Ok(())
}
```

</Accordion>

</AccordionGroup>
