CustomToken plugin
From LimeSurvey Manual
Introduction
CustomToken is a core plugin that lets you control the format of the access codes (tokens) that LimeSurvey automatically generates for participants in your survey participants table.
By default, LimeSurvey generates access codes using a mix of upper- and lowercase letters and digits. Depending on how you distribute your survey, this default format may not always be practical — for example:
- Numeric-only codes may be easier to read out over the phone.
- Codes without ambiguous characters (like
0/Oor1/l/I) are easier to transcribe correctly on paper. - Uppercase-only codes may be easier to read in printed invitation letters.
The CustomToken plugin adds these alternative formats as a simple, per-survey option.
Activating the plugin
- Log in as an administrator and go to Configuration -> Plugin manager.
- Find customToken in the list of plugins.
- Click the toggle/status icon to enable it.
Once enabled, the plugin becomes available as an option in every survey's settings — it does not need to be configured separately for each survey unless you want a survey to actually use a custom format.
Configuring a survey to use a custom token format
- Open the survey you want to configure.
- Go to Settings -> Plugins.
- Locate the setting labeled Custom token.
- Choose one of the following options from the drop-down list:
| Option | Effect |
|---|---|
| No custom function for this survey (default) | Standard LimeSurvey token generation is used (mixed-case letters and digits). This plugin has no effect on this survey. |
| Numeric tokens | Access codes consist only of the digits 1–9 (no zero, to avoid confusion with the letter O). |
| Without ambiguous characters | Access codes are generated normally, but characters that are easily confused with one another (such as 0/O, 1/l/I) are replaced with less ambiguous alternatives.
|
| Uppercase only | Access codes consist only of uppercase letters A–Z. |
This setting applies only to the survey you configured it in. Other surveys keep using the default token format unless you set this option for them individually.
Interaction with the access code length setting
The length of generated access codes is still determined by the survey's Access code length setting (found in the survey's participant/token settings). CustomToken does not override this value — it only changes the pool of characters used to fill that length.
For example, if a survey's access code length is set to 6 and you select Numeric tokens, participants will receive 6-digit numeric codes such as 483729.
When does the new format apply?
The selected format is used every time a new access code is generated for that survey.
Uniqueness of access codes is still guaranteed by LimeSurvey itself: if a newly generated code happens to already exist in the survey, the system automatically generates another one until a unique code is found. This behavior is unaffected by the CustomToken plugin.
Security note
The Uppercase only format uses a cryptographically secure random number generator whenever the server environment supports it. On servers where this is not available, it falls back to a standard (non-cryptographic) random number generator. In practice this is not a concern for typical survey invitation use cases, but it is worth being aware of if access codes are used in a context with strict security requirements.
Deactivating the plugin
If you disable the CustomToken plugin in the Plugin manager, any surveys that had a custom token format selected will revert to generating access codes using the standard LimeSurvey default format. The per-survey setting itself is also cleared when the plugin is deactivated.