> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.getunleash.io/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server.

# Create a project API token.

POST https://app.unleash-instance.example.com/api/admin/projects/{projectId}/api-tokens
Content-Type: application/json

Endpoint that allows creation of [project API tokens](https://docs.getunleash.io/concepts/api-tokens-and-client-keys#api-token-visibility) for the specified project.

Reference: https://docs.getunleash.io/api/create-project-api-token

## Authentication

- `Authorization` header (required) — API key needed to access this API
- `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format

## Request

### Path parameters

- `projectId` (string, required)

### Body (application/json)

- `type` (string, required) — A client or frontend token. Must be one of the strings "client" (deprecated), "backend" (preferred over "client") or "frontend" (not case sensitive).
- `tokenName` (string, required) — A unique name for this particular token
- `environment` (string, optional, default: default) — The environment that the token should be valid for. Defaults to "default".
- `expiresAt` (string, optional) — The date and time when the token should expire. The date should be in ISO 8601 format.

## Response

### 201

The resource was successfully created.

- `tokenName` (string, required) — A unique name for this particular token
- `type` (enum, required) — The type of API token
  - Allowed values: `client`, `admin`, `frontend`, `backend`
- `projects` (list of string, required) — The list of projects this token has access to. If the token has access to specific projects they will be listed here. If the token has access to all projects it will be represented as `[*]`
- `createdAt` (string, required) — When the token was created.
- `secret` (string, optional, nullable) — The token used for authentication.
- `environment` (string, optional, default: development) — The environment the token has access to.
- `project` (string, optional) — The project this token belongs to.
- `expiresAt` (string, optional, nullable) — The token's expiration date. NULL if the token doesn't have an expiration set.
- `seenAt` (string, optional, nullable) — When the token was last seen/used to authenticate with. NULL if the token has not yet been used for authentication.
- `alias` (string, optional, nullable) — Alias is no longer in active use and will often be NULL. It's kept around as a way of allowing old proxy tokens created with the old metadata format to keep working.
- `secure` (boolean, optional, nullable) — True if using the new api token format. This means copy token will no longer work

## Examples

**Request**

```json
{
  "type": "frontend",
  "tokenName": "some-user"
}
```

**Response**

```json
{
  "tokenName": "some-user",
  "type": "client",
  "projects": [
    "developerexperience",
    "enterprisegrowth"
  ],
  "createdAt": "2023-04-19T08:15:14.000Z",
  "secret": "project:environment.xyzrandomstring",
  "environment": "development",
  "project": "developerexperience",
  "expiresAt": "2023-04-19T08:15:14.000Z",
  "seenAt": "2023-04-19T08:15:14.000Z",
  "alias": "randomid-or-some-alias",
  "secure": true
}
```

**SDK Code**

```python
import requests

url = "https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens"

payload = {
    "type": "frontend",
    "tokenName": "some-user"
}
headers = {
    "Authorization": "<apiKey>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens';
const options = {
  method: 'POST',
  headers: {Authorization: '<apiKey>', 'Content-Type': 'application/json'},
  body: '{"type":"frontend","tokenName":"some-user"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens"

	payload := strings.NewReader("{\n  \"type\": \"frontend\",\n  \"tokenName\": \"some-user\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "<apiKey>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = '<apiKey>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"type\": \"frontend\",\n  \"tokenName\": \"some-user\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens")
  .header("Authorization", "<apiKey>")
  .header("Content-Type", "application/json")
  .body("{\n  \"type\": \"frontend\",\n  \"tokenName\": \"some-user\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens', [
  'body' => '{
  "type": "frontend",
  "tokenName": "some-user"
}',
  'headers' => [
    'Authorization' => '<apiKey>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "<apiKey>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"type\": \"frontend\",\n  \"tokenName\": \"some-user\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "<apiKey>",
  "Content-Type": "application/json"
]
let parameters = [
  "type": "frontend",
  "tokenName": "some-user"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/projects/projectId/api-tokens")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```