Delegating access for requesting seeds and accessing tools
Last updated 29 Jul 2026
Seeds are sensitive, so only people authorised for an order can download them. As the order owner, you can grant that access to additional colleagues by email address — for seed downloads and for owner-only tools. Whoever places the order is authorised automatically; everyone else must be added by the order owner using the steps below. This page covers granting access; the download itself is described in Requesting factory-set seeds.
How to delegate access
- Open the order. Sign in to your Token2 account and open the order you want to share access to.
- Add the authorised email addresses. In the order’s access settings, enter the email address of each person who should be able to request seeds. Add one address per line, or separate them with commas.
- Save. The listed addresses are now authorised for this order.
- Each person signs in with a matching account. To use their access, each delegated person creates (or signs in to) a Token2 account using the same email address you authorised. The order then appears in their account automatically.
Guest orders too: orders placed in guest mode using an email address will also appear once an account is created with that address — alongside any orders delegated to it.
What a delegated user can and can’t see
A delegated user can:
- See the order in their own account.
- Request and download the seeds, in any available format.
A delegated user can’t:
- See the order’s price details — pricing is hidden from delegated addresses.
- Manage the order or change who else has access — that stays with the owner.
Removing access: remove an address from the order’s access list at any time. When you do, that order disappears from that person’s account and they can no longer download its seeds. Access is only ever as current as your list.
Setting authorised users at order time
You don’t have to wait until after purchase. You can name additional authorised email addresses up front:
- When placing an order, add the addresses in the Additional info field at checkout.
- If you order via a purchase order, list the authorised email addresses on the PO.
You can still add or remove addresses later from the order, as above.
⚠ Delegate carefully. Anyone you authorise can download the token seeds for that order, which are the secret keys to those tokens. Only delegate to people who genuinely need them, and remove access when it’s no longer required.
Frequently asked questions
Does the delegated person need their own account?
Yes. They create a Token2 account with the exact email address you authorised. The order then appears in their account automatically — no separate link needed.
Can a delegated user see what we paid?
No. Price details are hidden for delegated addresses. They can request seeds but not view order pricing.
I added an address but they still can’t see the order.
Check that the address on the order’s access list exactly matches the address on their Token2 account, and that they’re signed in to that account. A mismatch (a typo, or a different alias) is the usual cause.
What happens if I remove someone?
The order immediately disappears from their account and they lose the ability to download its seeds. You can re-add them later if needed.
Seed request procedures
- Requesting factory-set seeds for Token2 hardware tokens
- Delegating access for requesting seeds (this page)
- Security of the TOTP hardware token secret keys
- How to generate your own seeds