Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

List quorum tokens using CloudHSM CLI

Focus mode
List quorum tokens using CloudHSM CLI - AWS CloudHSM

Use the quorum token-sign list command in CloudHSM CLI to list all token-sign quorum tokens present in your AWS CloudHSM cluster. This includes tokens generated by other users. A token is bound to a user, so while you may see tokens from other users, you will only be able to use tokens associated with the currently logged in user.

For more information about service types and names, see Service names and types that support quorum authentication. For more information about the content displayed from listed tokens, see Key management and usage with quorum authentication enabled for AWS CloudHSM using CloudHSM CLI for tokens associated with key-management and key-usage services, and see User management with quorum authentication enabled for AWS CloudHSM using CloudHSM CLI for tokens associated with user, quorum, or cluster service, respectively.

User type

The following users can run this command.

  • Admin

  • Crypto user (CU)

Syntax

aws-cloudhsm > help quorum token-sign list List the token-sign tokens in your cluster Usage: quorum token-sign list Options: --cluster-id <CLUSTER_ID> Unique Id to choose which of the clusters in the config file to run the operation against. If not provided, will fall back to the value provided when interactive mode was started, or error -h, --help Print help

Example

This command will list all token-sign tokens present in your AWS CloudHSM cluster. This includes tokens generated by other users. A token is bound to a user, so while you may see tokens from other users, you will only be able to use tokens associated with the currently logged in user.

aws-cloudhsm > quorum token-sign list { "error_code": 0, "data": { "tokens": [ { "username": "admin", "service": "quorum", "approvals-required": 2, "number-of-approvals": 0, "token-timeout-seconds": 397, "cluster-coverage": "full" }, { "username": "admin", "service": "user", "approvals-required": 2, "number-of-approvals": 0, "token-timeout-seconds": 588, "cluster-coverage": "full" }, { "username": "crypto_user1", "service": "key-management", "key-reference": "0x00000000002c33f7", "minimum-token-count": 1 }, { "username": "crypto_user1", "service": "key-usage", "key-reference": "0x00000000002c33f7", "minimum-token-count": 1 } ] } }

Related topics

On this page

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.