---
title: "POST /api/v1/agent-vault/sessions"
method: POST
path: "/api/v1/agent-vault/sessions"
tags: ["Agent Vault Sessions"]
---

# POST /api/v1/agent-vault/sessions

`POST /api/v1/agent-vault/sessions`

Create an Agent Vault session with an access bundle you can reach

## Request body

- object
  - `accessBundles` string[], required — The access bundle this session carries, by name. A list that accepts exactly one name.
  - `ttl` string — How long the session lasts: a duration such as 30m, 8h or 7d (at least 1m), or never. Defaults to 7d.

## Response `200`

Default Response

- object
  - `session` object, required
    - `id` string, uuid, required — The ID of the session.
    - `token` string, required — The session token. Returned once, at mint, and never again.
    - `expiresAt` string, date-time, nullable, required — When the session expires, or null when it never does.
    - `createdAt` string, date-time, required
    - `accessBundles` object[], required
      - `id` string, uuid, nullable, required
      - `name` string, required
      - `position` number, required

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

## Changes

- **2026-09-22** `62b0ba9edfe9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/infisical/apis/infisical-api/changes/api/v1/agent-vault/sessions/post.md)

---

[API](https://skmtc.dev/infisical/apis/infisical-api.md) · [All operations](https://skmtc.dev/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc.dev/infisical/apis/infisical-api/revisions/3f1f969fcbcb?raw)
