Renew the ClearPass SentinelOne API Token
Overview
The ClearPass service user in SentinelOne uses the Clear Pass Read-Only role. This role provides the minimum permissions required for the ClearPass integration.
The SentinelOne API token used by ClearPass expires after one year. A scheduled TeamDynamix ticket is created every 320 days. This provides a 45-day renewal buffer before the current token expires.
Use the following steps to regenerate the API token and update the token and expiration date in Password State.
SentinelOne Console
- Sign in to the SentinelOne console.
- Confirm that you are at the Account level.
- Go to Policies and Settings > User Management > Service Users.
- Locate the ClearPass service user.
- Select Actions > Regenerate API Token.
- Set Expiry to 1 Year.
- Regenerate the token.
- Copy the new API Token.
- Note the token’s expiration date.
⚠️ Security: Treat the API token as a credential. Store it only in the approved password management system. Do not place the token in TeamDynamix ticket notes.
Password State
- Sign in to Password State.
- Go to Automation > API Keys.
- Locate svc_ClearPass (cppm) for S1 API.
- Update the API token with the newly generated SentinelOne token.
- Update the expiration date to match the expiration date shown in SentinelOne.
- Save the changes.
Verification
After saving the new token, confirm that:
- The API token in Password State is current.
- The expiration date in Password State matches SentinelOne.
- ClearPass can continue communicating with SentinelOne successfully.