---
title: "Create a Scim Token"
method: POST
path: "/org/v2/scim-tokens"
tags: ["Scim Tokens (org/v2)"]
---

# Create a Scim Token

`POST /org/v2/scim-tokens`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to create a scim token.

## Request body

- object
  - `expire_duration_mins` integer — The duration in minutes after which the token expires. Defaults to 6 months (259200 minutes) if not specified. Minimum: 1 month (43200 minutes). Maximum: 2 years (1051200 minutes).

## Response `201`

A Scim Token was created.

- OrgV2ScimToken — `ScimToken` objects represent bearer tokens used for SCIM 2.0 API authentication. The token value is only returned when the token is first created and cannot be retrieved later. ## The Scim Tokens Model <SchemaDefinition schemaRef="#/components/schemas/org.v2.ScimToken" />
  - `api_version` 'org/v2' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'ScimToken' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `connection_name` string — The SSO connection name associated with this token.
  - `token` string — The SCIM bearer token. Only provided in create responses, not in `list`.
  - `created_at` string, date-time — The date and time when the token was created.
  - `expires_at` string, date-time — The date and time when the token expires.

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `403` — The access credentials were considered insufficient to grant access
- `409` — The request is in conflict with the current server state
- `422` — Validation Failed
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

## Changes

- **2026-09-18** `83f5e4fbfe08` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/confluent/apis/confluent-cloud-apis/changes/org/v2/scim-tokens/post.md)

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc.dev/confluent/apis/confluent-cloud-apis/revisions/83f5e4fbfe08?raw)
