[Yandex Cloud documentation](../../../index.md) > [Yandex IoT Core](../../index.md) > [Step-by-step guides](../index.md) > Managing passwords > Managing device passwords

# Managing device passwords

{% note warning %}

Yandex IoT Core is no longer available to new users. 

Current users can create resources until November 1, 2026. Afterwards, the service will go read-only and cease to operate on December 1, 2026. For more information on the timing and procedure, see [Service shutdown](../../sunset.md).

{% endnote %}

For devices and registries to begin exchanging data and commands, you need to [log in](../../concepts/authorization.md). This section describes how to manage device passwords for the appropriate authorization method.

{% note info %}

When using an X.509 certificate along with a password, the password has higher priority.

{% endnote %}

* [Adding a password](#create-or-add)
* [Viewing a password list](#list)
* [Deleting a password](#delete)

## Adding a password to a device {#create-or-add}

You can add a password to an already created device or set it when creating a device using the `--password` parameter.

{% note info %}

You can also set a password from the input stream. To do this, use the `--read-password` flag instead of the `--password` parameter.

{% endnote %}

### Adding a password to an existing device {#add}

{% list tabs group=instructions %}

- Management console {#console}

   To add a password to an existing device:

   1. In the [management console](https://console.yandex.cloud), select the folder where you want to add a password for an existing device.
   1. Navigate to **IoT Core**.
   1. Select the registry with the required device from the list.
   1. Select **Devices** in the left pane of the window.
   1. Select the device from the list.
   1. Under **Passwords**, click **Add password**.
   1. In the **Password** field, enter the password you will be using to access your device.<br/>You can use a [password generator](https://passwordsgenerator.net/) to create a password.<br/>Make sure you save the password, as you will need it later.
   1. Click **Add**.

- CLI {#cli}
  
    If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).

    To add a password: 
    1. Get a list of devices in the registry: 
    
        ```
        yc iot device --registry-name my-registry list
        ```
		
		Result:
		```
		+----------------------+--------+
        |          ID          |  NAME  |
        +----------------------+--------+
        | arenak5ciqss******** | second |
        | areqjd6un3af******** | first  |
        +----------------------+--------+
        ```    
    1. Add a password to the device:
    
        ```
        yc iot device password add --device-name first --password Passw0rdForDevice
        ```
		
		Result:
		```
		device_id: areqjd6un3af********
        id: areqjd6un3af********
        created_at: "2019-12-16T15:11:36.892167Z"
        ```

- Terraform {#tf}

  With [Terraform](https://www.terraform.io/), you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.
  
  Terraform is distributed under the [Business Source License](https://github.com/hashicorp/terraform/blob/main/LICENSE). The [Yandex Cloud provider for Terraform](https://github.com/yandex-cloud/terraform-provider-yandex) is distributed under the [MPL-2.0](https://www.mozilla.org/en-US/MPL/2.0/) license.
  
  For more information about the provider resources, see the guides on the [Terraform](https://www.terraform.io/docs/providers/yandex/index.html) website or [its mirror](../../../terraform/index.md).
  
  If you do not have Terraform yet, [install it and configure the Yandex Cloud provider](../../../tutorials/infrastructure-management/terraform-quickstart.md#install-terraform).
  
  
  To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), [authenticate](../../../terraform/authentication.md) using the appropriate method.

  To add a password to a device created using Terraform:
  
  1. In the configuration file, describe the parameters of the resource to create:

     * `yandex_iot_core_device`: Device properties:
       * `registry_id`: [ID of the registry](../registry/registry-list.md#registry-list) where the device was created.
       * `name`: [Device name](../device/device-list.md#device-list).
       * `description`: Device description.
       * `passwords`: List of passwords for authentication with a [username and password](../../concepts/authorization.md#log-pass).

      Here is an example of the resource structure in the configuration file:

      ```hcl
      resource "yandex_iot_core_device" "my_device" {
        registry_id = "<registry_ID>"
        name        = "<device_name>"
        description = "test device for terraform provider documentation"
      ...
        passwords = [
          "<password>",
        ]
      ...
      }
      ```

      For more on the properties of the `yandex_iot_core_device` resource, see [this provider guide](../../../terraform/resources/iot_core_device.md).
  1. In the command line, change to the folder where you edited the configuration file.
  1. Make sure the configuration file is correct using this command:

      ```bash
      terraform validate
      ```
     
      If the configuration is valid, you will get this message:
     
      ```bash
      Success! The configuration is valid.
      ```

  1. Run this command:

      ```bash
      terraform plan
      ```
  
      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
  1. Apply the configuration changes:

      ```bash
      terraform apply
      ```
     
  1. Type `yes` and press **Enter** to confirm the changes.

      You can verify device passwords in the [management console](https://console.yandex.cloud) or using this [CLI](../../../cli/quickstart.md) command:

      ```bash
      yc iot device password list --device-name <device_name>
      ```

- API {#api}

  To add a password to a device, use the [addPassword](../../api-ref/Device/addPassword.md) REST API method for the [Device](../../api-ref/Device/index.md) resource or the [DeviceService/AddPassword](../../api-ref/grpc/Device/addPassword.md) gRPC API call.

{% endlist %}

### Setting a password for a device when creating it {#create}

{% list tabs group=instructions %}

- Management console {#console}

   For information about how to set a password for a device when creating it, see [Creating a device](../device/device-create.md).

- CLI {#cli}
  
    If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).
    
    The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
    
    To set a password when creating a device:
    1. Get a list of registries in the folder: 
        
        ```
        yc iot registry list
		```
		
		Result:
		```
        +----------------------+-------------------+
        |          ID          |       NAME        |
        +----------------------+-------------------+
        | arenou2oj4ct******** | my-registry       |
        +----------------------+-------------------+
        ```
    1. Create a device with a password:       
    
        ```
        yc iot device create --registry-name my-registry --name device-with-pass --password Passw0rdForDevice
        ```
		
		Result:
		```
		id: arepomfambsg********
        registry_id: arenou2oj4ct********
        created_at: "2019-12-16T15:18:39.358922Z"
        name: device-with-pass
        ```

- Terraform {#tf}

   For information about how to set a password for a device when creating it, see [Creating a device](../device/device-create.md).

- API {#api}

  To set a password for a device when creating it, use the [create](../../api-ref/Device/create.md) REST API method for the [Device](../../api-ref/Device/index.md) resource or the [DeviceService/Create](../../api-ref/grpc/Device/create.md) gRPC API call.

{% endlist %}

## Getting a list of device passwords {#list}

{% list tabs group=instructions %}

- Management console {#console}

   To view the list of device passwords:

   1. In the [management console](https://console.yandex.cloud), select the folder to get the list of device passwords for.
   1. Navigate to **IoT Core**.
   1. Select the registry with the required device from the list.
   1. Select **Devices** in the left pane of the window.
   1. Select the device from the list.
   1. On the **Overview** page, go to the **Passwords** section.

   The list of device passwords will be displayed in the **Passwords** section.

- CLI {#cli}
  
    If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).
    
    The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
    
    To get a list of passwords:  
    1. Get a list of devices in the registry: 
    
        ```
        yc iot device --registry-name my-registry list
        ```
		
		Result:
		```
		+----------------------+------------------+
        |          ID          |       NAME       |
        +----------------------+------------------+
        | arenak5ciqss******** | second           |
        | arepomfambsg******** | device-with-pass |
        | areqjd6un3af******** | first            |
        +----------------------+------------------+
        ```
    1. Get a list of device passwords: 
    
        ```
        yc iot device password list --device-name device-with-pass
        ```
		
		Result:
		```
		+----------------------+---------------------+
        |          ID          |     CREATED AT      |
        +----------------------+---------------------+
        | areuin5t7pnd******** | 2019-12-16 15:18:39 |
        +----------------------+---------------------+
        ```

- API {#api}

  To get a list of device passwords, use the [listPasswords](../../api-ref/Device/listPasswords.md) REST API method for the [Device](../../api-ref/Device/index.md) resource or the [DeviceService/ListPasswords](../../api-ref/grpc/Device/listPasswords.md) gRPC API call.

{% endlist %}
   
## Deleting a device password {#delete}

{% list tabs group=instructions %}

- Management console {#console}

   To delete a device password:

   1. In the [management console](https://console.yandex.cloud), select the folder to delete a device password from.
   1. Navigate to **IoT Core**.
   1. Select the registry with the required device from the list.
   1. Select **Devices** in the left pane of the window.
   1. Select the device from the list.
   1. In the row with the password, click ![image](../../../_assets/console-icons/ellipsis.svg) and select **Delete** from the drop-down list.
   1. In the window that opens, click **Delete**.

- CLI {#cli}
  
    If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).
    
    The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
    
    To delete a password:  
    1. Get a list of device passwords: 
    
        ```
        yc iot device password list --device-name device-with-pass
        ```
		
		Result:
		```
		+----------------------+---------------------+
        |          ID          |     CREATED AT      |
        +----------------------+---------------------+
        | areuin5t7pnd******** | 2019-12-16 15:18:39 |
        +----------------------+---------------------+
        ```
    1. Delete the password: 
        ```
        yc iot device password delete --device-name device-with-pass --password-id areuin5t7pnd********
        ```
    1. Make sure that the password was deleted: 
        
        ```
        yc iot device password list --device-name device-with-pass
        ```
		
		Result:
		```
		+----+------------+
        | ID | CREATED AT |
        +----+------------+
        +----+------------+
        ```

- Terraform {#tf}

  With [Terraform](https://www.terraform.io/), you can quickly create a cloud infrastructure in Yandex Cloud and manage it using configuration files. These files store the infrastructure description written in HashiCorp Configuration Language (HCL). If you change the configuration files, Terraform automatically detects which part of your configuration is already deployed, and what should be added or removed.
  
  Terraform is distributed under the [Business Source License](https://github.com/hashicorp/terraform/blob/main/LICENSE). The [Yandex Cloud provider for Terraform](https://github.com/yandex-cloud/terraform-provider-yandex) is distributed under the [MPL-2.0](https://www.mozilla.org/en-US/MPL/2.0/) license.
  
  For more information about the provider resources, see the guides on the [Terraform](https://www.terraform.io/docs/providers/yandex/index.html) website or [its mirror](../../../terraform/index.md).
  
  If you do not have Terraform yet, [install it and configure the Yandex Cloud provider](../../../tutorials/infrastructure-management/terraform-quickstart.md#install-terraform).
  
  
  To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), [authenticate](../../../terraform/authentication.md) using the appropriate method.

  To delete the password of a device created using Terraform:
  
  1. Open the Terraform configuration file and delete the password value in the `passwords` section, in the device description fragment. To delete all passwords, delete the entire `passwords` section.

      Example device description in the Terraform configuration:

      ```hcl
      resource "yandex_iot_core_device" "my_device" {
        registry_id = "<registry_ID>"
        name        = "<device_name>"
        description = "test device for terraform provider documentation"
      ...
        passwords = [
          "<password>",
        ]
      ...
      }
      ```

      For more on the properties of the `yandex_iot_core_device` resource, see [this provider guide](../../../terraform/resources/iot_core_device.md).
  1. In the command line, change to the folder where you edited the configuration file.
  1. Make sure the configuration file is correct using this command:

      ```bash
      terraform validate
      ```
     
      If the configuration is valid, you will get this message:
     
      ```bash
      Success! The configuration is valid.
      ```

  1. Run this command:

      ```bash
      terraform plan
      ```
  
      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
  1. Apply the configuration changes:

      ```bash
      terraform apply
      ```
     
  1. Type `yes` and press **Enter** to confirm the changes.

      You can verify device passwords in the [management console](https://console.yandex.cloud) or using this [CLI](../../../cli/quickstart.md) command:

      ```bash
      yc iot device password list --device-name <device_name>
      ```

- API {#api}

  To delete a device password, use the [deletePassword](../../api-ref/Device/deletePassword.md) REST API method for the [Device](../../api-ref/Device/index.md) resource or the [DeviceService/DeletePassword](../../api-ref/grpc/Device/deletePassword.md) gRPC API call.

{% endlist %}