Like Kerberos tickets, AFS tokens contain authentication information and are automatically gotten for you during login and destroyed upon logout. However, they are not the same; as their name suggests, AFS tokens apply only to AFS, whereas Kerberos tickets are used for authentication to other MIT servers.
If you want to get AFS tokens manually, you can type aklog, optionally followed by a list of cells or paths to authenticate to. (For instance, aklog sipb.mit.edu will authenticate you to the SIPB cell, and aklog /mit/sipb will authenticate you to the SIPB locker.) You can verify that this worked by running the command tokens.
Your tokens should automatically expire at the same time your tickets do; if you need new tokens, renew will get them for you. ( renew is the one command that works with both tickets and tokens.)
If you manually get tokens, you should run unlog when you are done to destroy them.