# API & Session Management

Manage programmatic access and session security. Use this section to create/rotate API tokens for automation and to set session timeout policies.

* [API Tokens](https://docs.duplocloud.com/docs/automation-platform/access-control/api-and-session-management/api-tokens) — Create, scope, and rotate tokens for CLI/automation.
* [Session Timeout](https://docs.duplocloud.com/docs/automation-platform/access-control/api-and-session-management/session-timeout) — Configure portal session length and inactivity limits.
