> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create token

> Creates a first-party API token. Omit `user_id` (or set it to the
caller's ID) to create a token for yourself. Set `user_id` to a service
user's ID to mint a token that authenticates as that service user.
Creating a token for another human user is not allowed.

The `signed_token` value in the response is the secret credential and is
only returned once at creation time.




## OpenAPI

````yaml https://app.opal.dev/openapi.yaml post /tokens
openapi: 3.1.0
info:
  contact:
    email: hello@opal.dev
    name: Opal Team
    url: https://www.opal.dev/
  description: >-
    The Opal API is a RESTful API that allows you to interact with the Opal
    Security platform programmatically.
  title: Opal API
  version: '1.0'
servers:
  - description: Production
    url: https://api.opal.dev/v1
security: []
tags:
  - name: access-rules
    description: Operations related to access rules
  - name: apps
    description: Operations related to apps
  - name: bundles
    description: Operations related to bundles
  - name: campaigns
    description: Operations related to access review campaigns
  - name: configuration-templates
    description: Operations related to configuration templates
  - name: delegations
    description: Operations related to request reviewer delegations
  - name: event-streams
    description: Operations related to event streaming connections
  - name: events
    description: Operations related to events
  - name: groups
    description: Operations related to groups
  - name: group-bindings
    description: Operations related to group bindings
  - name: idp-group-mappings
    description: Operations related to IDP group mappings
  - name: message-channels
    description: Operations related to message channels
  - name: non-human-identities
    description: Operations related to non-human identities
  - name: on-call-schedules
    description: Operations related to on-call schedules
  - name: opal-queries
    description: Operations related to OpalQuery
  - name: opal-scripts
    description: Operations related to OpalScripts
  - name: owners
    description: Operations related to owners
  - name: requests
    description: Operations related to requests
  - name: resources
    description: Operations related to resources
  - name: paladin
    description: Operations related to Paladin
  - name: sessions
    description: Operations related to sessions
  - name: tags
    description: Operations related to tags
  - name: tokens
    description: Operations related to API tokens
  - name: uars
    description: Operations related to UARs. Deprecated in favor of the `campaigns` API.
  - name: users
    description: Operations related to users
paths:
  /tokens:
    post:
      tags:
        - tokens
      summary: Create token
      description: |
        Creates a first-party API token. Omit `user_id` (or set it to the
        caller's ID) to create a token for yourself. Set `user_id` to a service
        user's ID to mint a token that authenticates as that service user.
        Creating a token for another human user is not allowed.

        The `signed_token` value in the response is the secret credential and is
        only returned once at creation time.
      operationId: createToken
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateTokenInfo'
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateTokenResponse'
          description: The created API token. `signed_token` is only returned on creation.
        '400':
          description: Invalid request body.
        '403':
          description: Not authorized to create this token.
        '409':
          description: >
            Conflict — the target service user already has the maximum number of

            active API tokens (2). Delete an existing token before creating
            another.
      security:
        - BearerAuth: []
components:
  schemas:
    CreateTokenInfo:
      description: Information needed to create a first-party API token.
      type: object
      required:
        - token_label
        - access_level
      properties:
        token_label:
          description: A human-readable label for the token.
          example: My API Token
          type: string
        access_level:
          $ref: '#/components/schemas/ApiAccessLevelEnum'
        user_id:
          description: |
            The ID of the user the token should authenticate as. Omit or set to
            the caller's ID to create a personal token. Set to a service user's
            ID to mint a token for that service user.
          example: d4a7d928-783e-4599-8ec6-088d635a5bcc
          format: uuid
          type: string
        expires_at:
          description: Optional expiration time for the token.
          example: '2023-01-23T04:56:07.000Z'
          format: date-time
          type: string
    CreateTokenResponse:
      description: |
        The created API token. `signed_token` is the secret credential and is
        only returned once at creation time.
      type: object
      required:
        - token
        - signed_token
      properties:
        token:
          $ref: '#/components/schemas/Token'
        signed_token:
          description: |
            The secret token string. Store this securely; it is only returned
            once at creation time.
          type: string
          example: opal_pat_abc123...
    ApiAccessLevelEnum:
      description: The access level of an API token.
      enum:
        - READ_ONLY
        - FULL_ACCESS
      type: string
    Token:
      description: A first-party API token.
      example:
        token_id: f454d283-ca87-4a8a-bdbb-df212eca5353
        created_at: '2022-01-23T04:56:07.000Z'
        token_preview: ab123
        token_label: My API Token
        creator_user_id: d4a7d928-783e-4599-8ec6-088d635a5bcc
        user_id: d4a7d928-783e-4599-8ec6-088d635a5bcc
        access_level: READ_ONLY
      properties:
        token_id:
          description: The ID of the API token.
          example: f454d283-ca87-4a8a-bdbb-df212eca5353
          format: uuid
          type: string
        created_at:
          description: The date and time the token was created.
          example: '2022-01-23T04:56:07.000Z'
          format: date-time
          type: string
        token_label:
          description: A human-readable label for the token.
          example: My API Token
          type: string
        creator_user_id:
          description: The ID of the user who created the token.
          example: d4a7d928-783e-4599-8ec6-088d635a5bcc
          format: uuid
          type: string
        user_id:
          description: The ID of the user the token authenticates as.
          example: d4a7d928-783e-4599-8ec6-088d635a5bcc
          format: uuid
          type: string
        last_used_at:
          description: The date and time the token was last used.
          example: '2022-01-23T04:56:07.000Z'
          format: date-time
          nullable: true
          type: string
        access_level:
          $ref: '#/components/schemas/ApiAccessLevelEnum'
        expires_at:
          description: The date and time the token expires.
          example: '2023-01-23T04:56:07.000Z'
          format: date-time
          nullable: true
          type: string
      required:
        - token_id
        - created_at
        - token_label
        - creator_user_id
        - user_id
        - access_level
      type: object
  securitySchemes:
    BearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.