---
title: "Redeem token"
method: POST
path: "/cdx/v1/shared-tokens:redeem"
tags: ["Shared Tokens (cdx/v1)"]
---

# Redeem token

`POST /cdx/v1/shared-tokens:redeem`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Redeem the shared token for shared topic and cluster access information

## Request body

- object — Redeem share with token request parameters
  - `api_version` 'cdx/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'RedeemTokenRequest' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `token` string, required — The encrypted token
  - `aws_account` string — Consumer's AWS account ID for PrivateLink access.
  - `azure_subscription` string — Consumer's Azure subscription ID for PrivateLink access.
  - `gcp_project` string — Consumer's GCP project ID for Private Service Connect access.

## Response `200`

Consumer redeems shared token

- CdxV1RedeemTokenResponse — Share details for the consumer org or user
  - `api_version` 'cdx/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'RedeemTokenResponse' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `api_key` string — The api key
  - `secret` string — The api key secret
  - `kafka_bootstrap_url` string, uri — The kafka cluster bootstrap url
  - `schema_registry_api_key` string — The api key for schema registry
  - `schema_registry_secret` string — The api key secret for schema registry
  - `schema_registry_url` string, uri — The schema registry endpoint url
  - `resources` union[] — List of shared resources
    - union
      - object — The shared resource details
        - `kind` 'Topic', required — The shared resource kind
        - `topic` string, required — The topic name
      - object — The shared consumer group
        - `kind` 'Group', required — The resource kind
        - `group_prefix` string, required — The consumer group prefix
      - object — The shared resource details
        - `kind` 'Subject', required — The shared resource kind
        - `subject` string, required — The subject name

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `403` — The access credentials were considered insufficient to grant access
- `404` — Not Found
- `409` — The request is in conflict with the current server state
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
