> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/create-service-account-token/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Create a token for a service account. POST https://app.unleash-instance.example.com/api/admin/service-account/{id}/token Content-Type: application/json **Enterprise feature** Creates a new token for the service account identified by the id. Reference: https://docs.getunleash.io/api/create-service-account-token ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Request ### Path parameters - `id` (string, required) ### Body (application/json) This endpoint expects a createPatSchema. - `description` (string, required) — The PAT's description. - `expiresAt` (string, required) — The PAT's expiration date. ## Response ### 201 The resource was successfully created. - `id` (integer, required) — The PAT's ID. PAT IDs are incrementing integers. In other words, a more recently created PAT will always have a higher ID than an older one. - `createdAt` (string, required) — The date and time of when the PAT was created. - `description` (string, required) — The PAT's description. - `expiresAt` (string, required) — The PAT's expiration date. - `secret` (string, optional) — The token used for authentication. It is automatically generated by Unleash when the PAT is created and that is the only time this property is returned. - `seenAt` (string, optional, nullable) — When the PAT was last seen/used to authenticate with. `null` if it has not been used yet. - `userId` (integer, optional) — The ID of the user this PAT belongs to. - `expiryWarning` (enum, optional) — A warning about the expiration of this PAT, absent when there is nothing to warn about. `expires-soon` means the PAT is past the middle of its lifetime and expires within one of the configured `tokenExpiryNotificationDays` lead times; `expired` means it is no longer usable. - Allowed values: `expires-soon`, `expired` ## Errors ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 404 Not Found Error The requested resource was not found. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 409 Conflict Error The provided resource can not be created or updated because it would conflict with the current state of the resource or with an already existing resource, respectively. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 415 Unsupported Media Type Error The operation does not support request payloads of the provided type. Please ensure that you're using one of the listed payload types and that you have specified the right content type in the "content-type" header. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Examples **Request** ```json { "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z" } ``` **Response** ```json { "id": 1, "createdAt": "2023-04-19T08:15:14.000Z", "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z", "secret": "user:xyzrandomstring", "seenAt": "2023-04-19T08:15:14.000Z", "userId": 1337, "expiryWarning": "expires-soon" } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/service-account/id/token" payload = { "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z" } headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/service-account/id/token'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{"description":"user:xyzrandomstring","expiresAt":"2023-04-19T08:15:14.000Z"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/service-account/id/token" payload := strings.NewReader("{\n \"description\": \"user:xyzrandomstring\",\n \"expiresAt\": \"2023-04-19T08:15:14.000Z\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/service-account/id/token") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"description\": \"user:xyzrandomstring\",\n \"expiresAt\": \"2023-04-19T08:15:14.000Z\"\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://app.unleash-instance.example.com/api/admin/service-account/id/token") .header("Authorization", "") .header("Content-Type", "application/json") .body("{\n \"description\": \"user:xyzrandomstring\",\n \"expiresAt\": \"2023-04-19T08:15:14.000Z\"\n}") .asString(); ``` ```php request('POST', 'https://app.unleash-instance.example.com/api/admin/service-account/id/token', [ 'body' => '{ "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z" }', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/service-account/id/token"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"description\": \"user:xyzrandomstring\",\n \"expiresAt\": \"2023-04-19T08:15:14.000Z\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [ "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z" ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/service-account/id/token")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```