---
title: "Create an embed sign-in token"
method: POST
path: "/api/apps/{app_id}/embed-tokens"
---

# Create an embed sign-in token

`POST /api/apps/{app_id}/embed-tokens`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Creates a single-use sign-in token for a provisioned app user and returns `embed_url`, the chosen surface's address with the token on it. Load it in an iframe and the app opens signed in as that user. `live_preview` loads only while the app's sandbox is running. A workspace API key needs the **Mint embed sign-in tokens** permission. Limited to 300 requests a minute per app. Higher plans get a higher limit.

## Path parameters

- `app_id` string, required — ID of the app.

## Request body

- EmbedTokenPayload — The app user to mint for, and which of the app's surfaces to frame.
  - `email` string, email, required — The app user's email
  - `target` 'live_site' | 'latest_preview' | 'live_preview' — The surfaces a platform may frame, named by their ``UrlType``. A subset rather than ``UrlType`` itself: the rest of that enum is either internal (``platform``, ``pentest``) or addresses a revision, and a public payload should not offer what it will only refuse.

## Response `200`

Successful Response

- EmbedTokenResponse — A single-use sign-in token, and the URL that spends it.
  - `token` string, required — The single-use sign-in token. Already on `embed_url`; you don't need to send it anywhere yourself.
  - `expires_in` integer, required — Seconds until the token expires.
  - `embed_url` string, required — The chosen surface's address with the token on it. Load it in an iframe.

## Other responses

- `400` — The app has no address for `target`: error.code app_not_deployed or app_has_no_slug.
- `401` — Missing or invalid credentials.
- `403` — The email belongs to the app's owner, an editor or a service account: error.code privileged_user.
- `404` — The email isn't provisioned for this app: error.code unknown_user.
- `422` — Validation Error
- `429` — The app went over its per-minute limit for embed sign-in tokens.

## Changes

- **2026-10-01** `e58d4ff7b1f8` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/idealspot/apis/base44-app-management-api/changes/api/apps/:app_id/embed-tokens/post.md)

---

[API](https://skmtc.dev/idealspot/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/idealspot/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/idealspot/apis/base44-app-management-api/revisions/7e64cda7d407?raw)
