---
title: "Create Opaque Token"
method: POST
path: "/api/cp/setup/opaque-tokens"
tags: ["Opaque Tokens"]
---

# Create Opaque Token

`POST /api/cp/setup/opaque-tokens`

Mints an opaque token. The plaintext is returned exactly once and cannot be retrieved again.

## Request body

- object
  - `name` string — User-facing label
  - `scope` string — Space-separated. Self-service creation may only grant: api:read, api:write
  - `audience` string — Resource to pin the token to. Omit for any allowed resource.
  - `expires_in` integer — Lifetime in seconds. Omit for a non-expiring token.

## Response `200`

Successful response

- unknown

## Other responses

- `400` — Bad Request - Invalid parameters or request body
- `401` — Authentication information is missing or invalid
- `403` — Access denied - insufficient permissions or dependency access failure
- `409` — Conflict - foreign key or unique constraint violation on write
- `500` — Internal server error

---

[API](https://skmtc.dev/connexcs/apis/connexcs-control-panel-api.md) · [All operations](https://skmtc.dev/connexcs/apis/connexcs-control-panel-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/connexcs/connexcs-control-panel-api/revisions/54bc2ed6edae/schema)
