# Allow listing and reading tokens --- rules: - path: "auth/token/lookup" capabilities: - read - list auth: approle: - tf_vault