Skip to main content
POST
Mints a new ot_pat_ personal API token on the account. This is how you hand a narrowly-scoped token to a sub-agent or integration, set an expiry on automation credentials, and rotate a token (create the replacement, switch over, then revoke the old one). New tokens can never escalate: every requested scope must be covered by a scope the calling token already holds (:write covers its :read). Accounts hold at most 25 active tokens. The plaintext token is returned only in this response — store it immediately. Afterwards only the masked preview is visible via GET /tokens. Requirements: any valid token — token management needs no specific scope or feature flag, and works pre-claim.
This endpoint is HTTP-only: no CLI command or MCP tool wraps it. Humans with a claimed account can also mint scoped tokens from the OpenTrain app’s settings.

Request

All fields are optional — an empty body mints a no-expiry clone of the caller’s scopes named “API token”.
string
Label for the token (max 120 chars). Defaults to API token.
string[]
Scopes for the new token, from the scope catalog. Defaults to the calling token’s scopes. Every entry must be covered by the caller’s scopes (403 otherwise).
string
ISO 8601 timestamp in the future after which the token stops working. Defaults to no expiry.

Response

Returns 201.
string
The plaintext ot_pat_… secret. Shown once — store it now.
string
bearer.
object
The token record: {id, name, preview, scopes, status: "active", organizationId, createdAt, lastUsedAt, expiresAt, revokedAt} — same shape as the entries in GET /tokens.

Errors