Skip to main content
Staff
January 22, 2025

Technical Tip: How to use the same api-token in different FortiGates

  • January 22, 2025
  • 2 replies
  • 1427 views
Description This article describes how to use the same api-token in different FortiGates.
Scope FortiGate.
Solution

The FortiGate API token is displayed only once upon creation and cannot be retrieved. The API token cannot be modified through the GUI or CLI. However, it is possible to restore the configuration for API users in the same FortiGate or on a different FortiGate.

 

  1. Back up the configuration of FortiGate-1.
  2. Open the FortiGate-1.conf file and find 'config system api-user'.
  3. Copy the configuration under 'config system api-user'.
  4. Back up the configuration of FortiGate-2.
  5. Openthe  'FortiGate-2.conf' file and find config system api-user, remove the existing settings and paste the copied settings from step 3.
    • Note: If 'config system api-user' is not present in FortiGate-2 backup, paste the settings at the end of the file.
  6. Confirm if an admin profile with the same name exists on FortiGate-2 under 'config system accprofile'. if not, it will be necessary to create it. Copy the acc-profile configuration from FortiGate-1 to FortiGate-2.
  7. Save the edited 'FortiGate-2.conf' file.
  8. A reboot is required to perform this step. Restore edited FortiGate-2 configuration: Configuration backup and restore (7.6.1)

 

If the API token is not regenerated, it will remain the same on both FortiGates.

 

Related document:

Using APIs

    2 replies

    vladimirtegeltija
    Visitor III
    May 29, 2026

    Hello Jfelix09,

     

    We were interested for your solution how to use same API key on multiple FortiGates at the same time. We found a simple way for this by the use of Forti Manager.

    You can simply do like this:

    • you just have to use your saved key from 1st device
    • and go to your Forti Manager, Device Manager and find your 2nd device
    • Go to CLI configurations posted bellow and enter your common key that you saved before
    • Push the changes.

     

    I will double check later is this possible to do via Forti Manager script configuration, like a BULK push to multiple devices at the same time.

    CLI template approach will not allow you to do achieve same result.

     

    What do you think, do you see any obstacles that we maybe face in the future?

    Thanks

    vladimirtegeltija
    Visitor III
    May 29, 2026

    I can confirm that it works also with usage of Forti Manager script executed on device database, then changes pushed to devices. In this way you can push same settings on all managed devices with few clicks.

     

     

    Any comments, do you see any obstacles with this approach?

     

    If not, can this be officially documented?

    Thank you!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!