---
title: "Mint an ephemeral session token for an ACP provider session"
method: POST
path: "/api/sessions/tokens"
tags: ["Sessions"]
---

# Mint an ephemeral session token for an ACP provider session

`POST /api/sessions/tokens`

Returns a short-lived aseph_ bearer for use by the ACP adapter in place of the full operator key. The token expires at the requested TTL and is actively revoked when the session ends. Only the operator key may mint session tokens.

## Request body

- object
  - `agentId` string, required
  - `taskId` string, required
  - `ttlMs` integer, required

## Response `200`

Minted token plaintext (returned once) and its stable token ID

- object
  - `tokenId` string, required
  - `plaintext` string, required

## Other responses

- `400` — Validation error
- `401` — Unauthorized

## Changes

- **2026-09-14** `5281393061a7` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/desplega-ai/apis/agent-swarm-api/changes/api/sessions/tokens/post.md)

---

[API](https://skmtc.dev/desplega-ai/apis/agent-swarm-api.md) · [All operations](https://skmtc.dev/desplega-ai/apis/agent-swarm-api/llms.txt) · [OpenAPI document](https://skmtc.dev/desplega-ai/apis/agent-swarm-api/revisions/01e2386c97da?raw)
