Home / Alt manpages / ip-token(8)

  • ip-token(8)
  • Admin command
  • linux

Pin IPv6 Interface Identifiers with ip token

Use ip token to give an IPv6 interface a predictable interface identifier while Router Advertisements continue to supply the network prefix. This is useful for servers that need a recognisable host part but should still follow automatic renumbering when the routed prefix changes.

Allow about 10 minutes. You need the iproute2 package and an interface that supports IPv6. Reading tokens is normally unprivileged. Setting or deleting a token changes kernel network state, so use an elevated shell for those operations and confirm the interface name before pressing Enter.

Checkpoint: identify the tool and interface

  1. Check the installed iproute2 version and list the interfaces available on this host.
ip -V
ip -o link show

On the machine used for these examples, the command reports iproute2-6.1.0. The interface names in your output will be different. Pick the interface that carries the IPv6 traffic, such as enp0s31f6, rather than assuming that the first interface is correct.

The local manpage describes the command as ip token, not as a separate executable. Its four useful operations are list, get, set and del. The bare command is also accepted by this installed version and lists tokens, but spelling out list makes scripts and notes clearer.

Checkpoint: inspect the current token

  1. Read the token for one known interface without changing anything.
ip token get dev enp0s31f6

Expected output has this shape:

token :: dev enp0s31f6

The :: value means that this interface currently has the zero token in the running kernel. It is output, not a placeholder that you should copy into a configuration file. If the interface has a configured token, the command prints the IPv6 token followed by dev and the interface name.

To see every interface token, run:

ip token list

The list includes interfaces such as bridges and virtual Ethernet devices when the kernel has token entries for them. That is normal. Filter the output mentally or with a separate read-only command if you are looking for one physical interface:

ip token list | grep -F ' dev enp0s31f6'

A missing interface produces an error instead of a useful result. Copy the name from ip -o link show, and remember that Linux interface names are case-sensitive.

Checkpoint: choose a token

  1. Choose an IPv6 interface identifier that is valid for your addressing plan and does not expose information you meant to keep private.

The token is the address used for the interface identifier, commonly the low 64 bits of an IPv6 address. A full IPv6 token such as ::1234:5678:90ab:cdef is easy to recognise. Do not paste a complete global address containing a network prefix just because it looks familiar. The purpose of this command is to set the interface identifier while SLAAC obtains the prefix from Router Advertisements.

Do not reuse the same token on two active interfaces on the same network. A predictable token is not an authentication mechanism, and it does not make an address private. Treat it as a routing and operations choice, not as a secret.

Checkpoint: set the token

  1. Apply the selected token to the intended interface from an elevated shell.
sudo ip token set ::1234:5678:90ab:cdef dev enp0s31f6

Successful ip commands normally print nothing. Verify the kernel value immediately:

ip token get dev enp0s31f6

Expected output is:

token ::1234:5678:90ab:cdef dev enp0s31f6

This operation changes the token held by the kernel. The manpage does not describe a persistent network-manager, systemd-networkd or distribution-specific configuration file, so do not assume that the setting will survive a reboot or a network service restart. If persistence matters, put the same command in the configuration mechanism that owns this interface, then test that mechanism separately.

Checkpoint: remove or replace it safely

  1. Remove the token only when you intend to return the interface to token-free behaviour.
sudo ip token del dev enp0s31f6
ip token get dev enp0s31f6

The delete operation changes kernel state and may alter which IPv6 addresses are formed after Router Advertisements are processed. It is not an undo button for addresses already advertised or used by applications. Stop or reconfigure services that depend on the old address before deleting a production token.

To undo a mistaken deletion, set the previous value again:

sudo ip token set ::1234:5678:90ab:cdef dev enp0s31f6
ip token get dev enp0s31f6

If you only want a different stable identifier, setting the new value directly is simpler than deleting first. Verify the result, then inspect the addresses on the interface with ip -6 address show dev enp0s31f6. That separate command shows addresses, while ip token get shows the token stored for the device.

Common failure modes

  • Wrong device: a valid command can still configure the wrong interface. Compare the device name with its link state and address output before using sudo.
  • Expecting a full address: the token does not replace the prefix learned from the network. Check Router Advertisements and IPv6 address assignment if no usable global address appears.
  • Expecting persistence: the command writes the running kernel state. Record the command in the interface manager's configuration only after confirming which service controls the link.
  • Confusing display with configuration: ip token list reports kernel state; it does not prove that a distribution configuration file will recreate it later.

Done means

  • ip -V identifies the installed iproute2 version.
  • ip token get dev INTERFACE shows the intended token.
  • ip -6 address show dev INTERFACE shows the resulting IPv6 addresses.
  • You know whether the setting is temporary or is recreated by your network configuration service.