The Carbon Black App Control server creates a hidden token that the Carbon Black EDR server uses to send back watchlist hits. This token is not visible in the console of either product, but can be retrieved from the database.
You can also enter the token manually on the Carbon Black EDR side for diagnostic purposes. If you think this token was compromised, or if your configuration stops working (for example, because the Carbon Black EDR server lost the token due to a reinstall or a manual token change), you can regenerate a new key.