Video | Tableau | Tool strategy | Analytics

Personal access token (PAT) admin control | New in Tableau 2023.2

Users have always been able to create personal access tokens — now admins finally get a say in how they work.

Part ofWhat's new in Tableau 2023.2
Watch on YouTube
  • Personal access tokens are long-lived authentication tokens that let users sign into the Tableau REST API without hard-coded username and password credentials, each consisting of a name, key and secret.
  • You create a PAT under account settings, where it's assigned an expiration date and a copyable secret that only you should know — and can be revoked instantly.
  • Admins can now enable or disable PAT creation site-wide, or restrict the ability to specific user groups for better oversight.
  • Admins can set an expiration period for tokens (180 days by default) to align with enterprise password cycle policies.
  • There's still no built-in interface to audit all created tokens or their usage, though some of this is available via Postgres repository data or Tableau's auditing capabilities.

Tableau 2023.2 gives admins actual control over personal access tokens (PATs) — before this, users could freely create them with no site-level oversight or governance.

PATs are long-lived authentication tokens that let users sign into the Tableau REST API without hard-coded username and password credentials. Each one has a name, a key and a secret, and until now admins had no way to manage how they were used across a site.

The Breakdown
  • What a PAT actually is 0:11

    A PAT replaces a username and password for REST API access — it's made up of a name, a key and a secret, and only the person creating it should ever know the secret.

  • Creating and revoking your own token 1:12

    You create a PAT under account settings, where it's given an expiration date and a one-time copyable secret; you can revoke it instantly from the same interface if it's ever exposed or no longer needed.

  • Admins can now switch PATs on or off 1:48

    In site settings under General, admins can enable or disable PAT creation site-wide, giving them oversight they didn't previously have over who can generate these credentials.

  • Set an expiration period 2:52

    Admins can set how long tokens remain valid before expiring — 180 days by default, but you can enter your own number to align with an enterprise password cycle policy.

  • No built-in audit view yet 3:16

    There's still no interface showing all tokens created or how they're being used; some of that visibility exists via Postgres repository data or Tableau's auditing capabilities, but not natively in this settings screen.

Worth Knowing
  • The token secret is shown only once at creation — copy it immediately, since Tableau won't show it again.
  • Settings changes (enabling/disabling PATs, restricting to a group, setting expiration) apply immediately once saved.
  • There's no native way to see a list of all PATs created across the site or track their usage frequency.
Use It When

Reach for this when you need to govern how service accounts or automation scripts authenticate against the Tableau REST API — for example enforcing an expiration policy or restricting PAT creation to a trusted admin group rather than leaving it open to everyone.

How this Rollup was made provenance & method

A Rollup is drafted by AI from the video's transcript, then reviewed and edited by Tim. Everything used to produce this one is listed below — the model, the exact prompt, and the source video — so the process is transparent and reproducible.

Transcription
On-device — NVIDIA Parakeet v3 for recent videos, OpenAI Whisper large-v3 for earlier ones. The transcript never leaves the machine or gets published.
Drafting
Claude Sonnet 5 in the cloud, from that transcript.
Prompt
The exact Rollup prompt (v2) — the full system prompt, unedited.
Source video
Watch on YouTube
Drafted
5 July 2026 at 09:38
Reviewed & edited
5 July 2026 at 09:41 · by Tim Ngwena

Model + prompt + video is everything you'd need to recreate a Rollup like this yourself. The one thing we don't share is the transcript.

Rights. The video and its transcript are the property of TN Media Ltd. Unauthorised use or download is prohibited. © TN Media Ltd.