Skip to main content
POST
Create token

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json

Information needed to create a first-party API token.

token_label
string
required

A human-readable label for the token.

Example:

"My API Token"

access_level
enum<string>
required

The access level of an API token.

Available options:
READ_ONLY,
FULL_ACCESS
user_id
string<uuid>

The ID of the user the token should authenticate as. Omit or set to the caller's ID to create a personal token. Set to a service user's ID to mint a token for that service user.

Example:

"d4a7d928-783e-4599-8ec6-088d635a5bcc"

expires_at
string<date-time>

Optional expiration time for the token.

Example:

"2023-01-23T04:56:07.000Z"

Response

The created API token. signed_token is only returned on creation.

The created API token. signed_token is the secret credential and is only returned once at creation time.

token
object
required

A first-party API token.

Example:
signed_token
string
required

The secret token string. Store this securely; it is only returned once at creation time.

Example:

"opal_pat_abc123..."

Last modified on October 8, 2026