CRYPTSETUP-TOKEN(8) (NAME) cryptsetup-token - LUKS2 (SYNOPSIS) cryptsetup token [<>] <> (DESCRIPTION) add (keyring) . . user user-session . token LUKS2 . (keyring) --key-description . (keyslot) --key-slot --key-slot . --token-id . : token remove keyring --token-id . import JSON LUKS2 . --json-file . --key-slot . export JSON --json-file . unassign . --token-id --key-slot . --token-id add import --token-replace . <> : [--header, --token-id, --key-slot, --key-description, --disable-external-tokens, --disable-locks, --disable-keyring, --json-file, --token-replace, --unbound, --external tokens-path]. (OPTIONS) --batch-mode, -q . ! --verify-passphrase . --debug --debug-json () . # . --debug-json JSON LUKS2 . --disable-external-tokens () LUKS2 . --disable-keyring (volume key) (keyring) dm-crypt . LUKS2 . --disable-locks . LUKS2 . : cryptsetup ( /run ) . --external-tokens-path < > cryptsetup ( ) . ( '/' ). --header < LUKS> (detached) LUKS . LUKS . LUKS ( luksAddKey) LUKS LUKS . --help, -? . --json-file JSON . --json-file=- JSON . --key-description (keyring) . --key-slot, -S <0-N> LUKS . LUKS . LUKS1 . LUKS2 LUKS2 . --token-id . ( ) . --token-replace --token-id . --unbound LUKS2 . add . --usage . --version, -V . (REPORTING BUGS) cryptsetup . --debug . (SEE ALSO) cryptsetup (FAQ) cryptsetup(8) integritysetup(8) veritysetup(8) (CRYPTSETUP) cryptsetup . cryptsetup 2.8.7 2026-07-21 CRYPTSETUP-TOKEN(8)