Skip to navigation

Mint an API token

Creates a bearer token for scripting the API without a browser session. Send it as Authorization: Bearer <token>.

The response is the only time the secret is shown. Store it immediately; if it is lost, revoke the token and mint another.

A token can never do more than its owner could through the UI: a read_write token is bounded by the intersection with the owner’s own permissions. A token is only accepted by the environment that issued it.

Authentication

AuthorizationBearer

JWT access token obtained from POST /api/v1/auth/login, or a finput_sk_... API token

Request

This endpoint expects an object.
namestringRequired
scopeenumRequired

read allows every GET, plus the five computation endpoints: POST /calculator, /calculator/recalculate, /calculator/abn-lookup, /matrix/ and /matrix-calculator/. Running those still consumes daily calculator/Matrix allowance and adds to the caller's own recents; what read prevents is changing data another request reads back, saved scenarios included. read_write additionally allows mutations. Both are bounded by the owner's own permissions — a token can never exceed what its owner could do in the UI.

Allowed values:
expires_in_daysenumRequired
Allowed values:

Response

Created — carries the secret, once

idintegerOptional
namestringOptional
token_idstringOptional
Public identifier, safe to log.
last_fourstringOptional
Last four characters, for recognising a token in a list.
scopeenumOptional

read allows every GET, plus the five computation endpoints: POST /calculator, /calculator/recalculate, /calculator/abn-lookup, /matrix/ and /matrix-calculator/. Running those still consumes daily calculator/Matrix allowance and adds to the caller's own recents; what read prevents is changing data another request reads back, saved scenarios included. read_write additionally allows mutations. Both are bounded by the owner's own permissions — a token can never exceed what its owner could do in the UI.

Allowed values:
environmentenumOptional
The environment this token was minted in. A token is only accepted by the environment that issued it.
Allowed values:
originenumOptional

How the token was created: ui from Settings, mcp by approving an AI assistant's connection request. Read-only — it cannot be set at mint time, and only mcp tokens are accepted at POST /mcp.

Allowed values:
created_atdatetimeOptional
expires_atdatetimeOptional
last_used_atdatetime or nullOptional
revoked_atdatetime or nullOptional
tokenstringOptional
The secret. Shown once, at creation, and never again.
warningstringOptional

Errors

400
Bad Request Error