---
title: "POST /api/tokens"
method: POST
path: "/api/tokens"
tags: ["token"]
---

# POST /api/tokens

`POST /api/tokens`

## Request body

- CreateTokenRequest
  - `expiresAt` string, date-time, nullable — Expiration date as a Unix timestamp (seconds since epoch)
  - `name` string, required — Name
  - `ownerOrg` string, uuid, nullable — UUID of the organization that should own this token
  - `ownerRepo` string, uuid, nullable — UUID of the repository that should own this token
  - `ownerUser` string, uuid, nullable — UUID of the user that should own this token. Can only ever be the creating user
  - `permissions` TokenPermission[], required — Permissions
  - `scope` 'all' | 'public' | 'selected'
  - `scopeOrgs` string[] — UUIDs of the organizations to limit this token to
  - `scopeRepos` string[] — UUIDs of the repositories to limit this token to
  - `tokenType` 'personal' | 'organization' | 'ci' | 'deploy' | 'runner' | 'instance', required

## Response `201`

Token created

- CreateTokenResponse
  - `secret` string, required — Token secret, will not be shown ever again
  - `token` TokenResponse, required
    - `creator` string, uuid, nullable — UUID of the user that created this token. Not used for scoping Unset once the creating user has been deleted
    - `expiresAt` string, date-time, nullable — Expiration
    - `id` string, uuid, required — ID
    - `lastUsedAt` string, date-time, nullable — Last used
    - `name` string, required — Name
    - `ownerOrg` string, uuid, nullable — UUID of the organization that owns this token Only set for `token_type` = `organization`
    - `ownerRepo` string, uuid, nullable — UUID of the repository that owns this token. Only set for `token_type` = \[`ci`, `deploy`, `runner?`]
    - `ownerUser` string, uuid, nullable — UUID of the user who owns this token Only set for `token_type` = `personal`
    - `permissions` TokenPermission[], required — Permissions
    - `revokedAt` string, date-time, nullable — Revocation
    - `scope` 'all' | 'public' | 'selected', required
    - `tokenType` 'personal' | 'organization' | 'ci' | 'deploy' | 'runner' | 'instance', required
    - `scopeOrgs` string[], required — UUIDs of the organizations this token is limited to
    - `scopeRepos` string[], required — UUIDs of the repositories this token is limited to

## Other responses

- `400` — Invalid owner, scope, permissions or expiration date
- `401` — Authentication required
- `403` — Insufficient permissions
- `409` — A token with this name already exists

## Changes

- **2026-09-20** `dc37a4c478f9` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/mari/apis/gitarena/changes/api/tokens/post.md)

---

[API](https://skmtc.dev/mari/apis/gitarena.md) · [All operations](https://skmtc.dev/mari/apis/gitarena/llms.txt) · [OpenAPI document](https://skmtc.dev/mari/apis/gitarena/revisions/dc37a4c478f9?raw)
