Skip to main content
Docs menu

Docs / Security & Privacy

Agent token and the Activity log

Go to Apps → Caro → Settings.

Agent token (redacted) and Activity log sections, with Regenerate highlighted

Agent token

The page describes it precisely: "Identifies this agent to its widget and API. Regenerating immediately invalidates the old one." This token is what authenticates requests from your widget (and any direct API usage) as belonging to this specific agent.

  • Copy — copies the token for use elsewhere (e.g. a custom integration).
  • Regenerate — issues a brand-new token and immediately invalidates the old one.

When to regenerate

Regenerate the token if you suspect it's been exposed — accidentally committed to a public code repository, shared in a support ticket, or pasted somewhere it shouldn't have been. Since regenerating invalidates the old token immediately, do this only when you're ready to also update anywhere else the old token was being used, or those integrations will break the moment you regenerate.

Treat it like a password

Never paste your agent token into a screenshot, public forum post, or anywhere else it could be captured — it's a real credential, not a display-only ID.

Activity log

"Recent changes made to this agent." A record of modifications to this agent's configuration — useful for understanding what changed and when, especially if more than one teammate has access to Settings. On a fresh setup, this shows "No activity recorded yet."