How to remove token from URLs

We added “DDoS attack protection” on our website for security reasons. The website is running very smoothly but our main concern is it created tokens. Whenever I visit my website in the URL section it often comes with a new token. Google Analytics also fetch this URL.

How can we remove these auto-generated tokens from the URLs so that we will not have any duplication penalty from Google? Please check the below image to check the auto-generated URL.

Are the canonical links being declared on each web page?

Search Google for “canonical duplicate URL”.

From memory they have suggestions to eliminate duplicates when a url passes size or colour parameters to a common web page

Yes, we have canonical links on each page.

I think the canonical links are being called incorrectly and would ckeck to ensure they strictly follow Google’s recomendations.

https://support.google.com/webmasters/answer/139066?hl=en