cPanel API tokens allow scripts or external tools to run supported cPanel API functions without storing the cPanel account password.
Current cPanel documentation labels the Manage API Tokens functionality as experimental, so details can change in future versions. Tokens can have expiration dates and can be revoked independently.
Use a separate token for each automation or integration when practical so one integration can be revoked without changing every other credential.