Create an embed sign-in token

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Creates a single-use sign-in token for a provisioned app user and returns embed_url, the chosen surface's address with the token on it. Load it in an iframe and the app opens signed in as that user. live_preview loads only while the app's sandbox is running. A workspace API key needs the Mint embed sign-in tokens permission. Limited to 300 requests a minute per app. Higher plans get a higher limit.

post/api/apps/{app_id}/embed-tokens

Path parameters

app_idstring required

ID of the app.

ID of the app.

Request body

emailstring email required

The app user's email

target'live_site' | 'latest_preview' | 'live_preview'

The surfaces a platform may frame, named by their UrlType.

A subset rather than UrlType itself: the rest of that enum is either internal (platform, pentest) or addresses a revision, and a public payload should not offer what it will only refuse.

Response

Successful Response

tokenstring required

The single-use sign-in token. Already on embed_url; you don't need to send it anywhere yourself.

expires_ininteger required

Seconds until the token expires.

embed_urlstring required

The chosen surface's address with the token on it. Load it in an iframe.

Example response

{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.sig",
  "expires_in": 60,
  "embed_url": "https://weekly-report.base44.app/?ott=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.sig"
}

Changes

Changed in 1 of the 35 revisions of this API.1