Skip to main content
Tokens

Create Token

Issue a scoped token. Use this to mint short-lived tokens that grant a client access to a single actor instead of sharing your namespace token.

Each grant names a resource type, a target ("any" or a specific { "id": ... }), and the operations it allows. The RivetKit client wraps this as handle.issueToken().

POST https://api.rivet.dev/auth/tokens

Examples

Authentication

Send your namespace token as a bearer token in the Authorization header. Every control plane request also requires the namespace query parameter. See Authentication.

Request Body

Content type: application/json.

FieldTypeRequiredDescription
durationinteger | nullNoLifetime in seconds. Omit for the default lifetime.
grantsobject[]YesPermissions the token carries.
grants[].operations("read" | "update" | "list" | "create" | "delete")[]YesOperations the token may perform on the target.
grants[].resource"namespace" | "actor" | "runner" | "runner_config" | "datacenter" | "actor_gateway" | "actor_kv"YesResource type the grant applies to.
grants[].target"any" | objectYes"any" for every resource of this type, or { "id": "..." } for one resource.
namespacestringYesNamespace the token is valid in.
subjectstring | nullNoFree-form subject to attach to the token, such as a user ID.

Responses

200

FieldTypeDescription
expires_tsintegerWhen the token expires, in Unix milliseconds.
issued_tsintegerWhen the token was issued, in Unix milliseconds.
tokenstringThe issued token. Treat it as a secret.
{
  "expires_ts": 1700000000000,
  "issued_ts": 1700000000000,
  "token": "sk_..."
}