Skip to main content
POST
Create a new API token

Body

application/json
signature
string
required

Ed25519 signature of the token creation request.

Message: createToken:<timestamp>:<expiresIn>:<name>:<userId> — data fields sorted alphabetically by key. Omitted optional fields become an empty slot (not a dropped slot):

  • name omitted → createToken:<ts>:<expiresIn>::<userId>
  • expiresIn omitted → createToken:<ts>::<name>:<userId>
  • both omitted → createToken:<ts>:::<userId>

Sign the UTF-8 bytes of the message with the Ed25519 private key whose public key is registered for the user. Encode the signature as lowercase hex, 128 chars, no 0x prefix.

Pattern: ^[0-9a-f]{128}$
Example:

"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2"

timestamp
integer
required

Unix timestamp in milliseconds. Must be within ±2 minutes of server time or the request is rejected with 401 Signature expired.

Required range: -9007199254740991 <= x <= 9007199254740991
userId
string<uuid>
required

User identifier. Send the value verbatim — do not re-case it, since the signed message must match byte-for-byte.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
expiresIn
integer

Token lifetime in seconds. Defaults to 604800 (7 days). Must be > 0. When > 604800, name is required.

Required range: -9007199254740991 <= x <= 9007199254740991
name
string

Token name. Required when expiresIn > 604800 (7 days). Must be unique per user. Tokens without a name are session tokens and are not enumerable.

Response

201 - application/json
expiresAt
string<date>
required

Token expiration date

Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))$
id
string
required

Token ID

token
string
required

Bearer token value