---
title: "AuthenticationToken:Create"
method: POST
path: "/v2/authenticationtokens"
tags: ["AuthenticationToken"]
---

# AuthenticationToken:Create

`POST /v2/authenticationtokens`

Creates a new authentication token under a merchant. You can also specify which authorisation groups needs to be linked to the token. You can also supply a merchantCode. If a merchantCode is supplied then you need to have access to that merchant. You need to authenticate with an AT-code as username and a token as password

## Request body

- AuthenticationTokenAuthenticationTokenInput — Creates a new authentication token under a merchant. You can also specify which authorisation groups needs to be linked to the token. You can also supply a merchantCode. If a merchantCode is supplied then you need to have access to that merchant. You need to authenticate with an AT-code as username and a token as password
  - `merchantCode` string — The merchant id of your company starting with M.
  - `authenticationToken` AuthenticationTokenAuthenticationTokenInputAuthenticationToken, required
    - `description` string — The description of the token
    - `authorisation` 'all' | 'specified' — Specify which kind of authorisation is applicable for the token all: all merchant rights specified: specify which authorisation groups should be enabled from the token. At least one authorisation group (in the authorisationGroups array) is mandatory
    - `authorisationGroups` string[] — The authorisation group codes
    - `ipFilter` AuthenticationTokenAuthenticationTokenInputAuthenticationTokenIpFilter
      - `type` 'DENY_FROM_ALL' | 'null', nullable — The type of the IP filter
      - `exceptionList` string[] — A list of IP addresses to be filtered on

## Response `201`

Created

- AuthenticationTokenAuthenticationTokenOutput
  - `code` string — The AT-code for an authentication token.
  - `secret` string — A 40 character secret
  - `name` string — The description of the token
  - `merchant` AuthenticationTokenAuthenticationTokenOutputMerchant
    - `code` string — The merchant id of your company starting with M.
    - `name` string — The name of the merchant.
    - `status` 'ACTIVE' | 'INACTIVE' — The status of the merchant.
  - `authorisation` 'all' | 'specified' — Specify which kind of authorisation is applicable for the token all: all merchant rights specified: specify which authorisation groups should be enabled from the token. At least one authorisation group (in the authorisationGroups array) is mandatory
  - `authorisationGroups` object — The authorisation group codes
  - `ipFilter` AuthenticationTokenAuthenticationTokenOutputIpFilter
    - `type` 'DENY_FROM_ALL' | 'null', nullable — The type of the IP filter
    - `exceptionList` object — A list of IP addresses to be filtered on
  - `createdAt` string, date-time, nullable — The date and time at which this entity was created in ISO-8601 (ATOM) notation
  - `createdBy` string, nullable — The reference to an account or token whom created the entity
  - `modifiedAt` string, date-time, nullable — The date and time at which this entity was modified in ISO-8601 (ATOM) notation.
  - `modifiedBy` string, nullable — The reference to an account or token whom modified this entity
  - `deletedAt` string, date-time, nullable — The date and time at which this entity was deleted in ISO-8601 (ATOM) notation.
  - `deletedBy` string, nullable — The reference to an account or token whom deleted the entity
  - `_links` LinkOutput[], nullable
    - `href` string, nullable — The URI to the linked resource
    - `rel` string, nullable — The name of the linked resource
    - `type` string, nullable — The (http(s)) method needed to approach the linked resource

## Other responses

- `400` — Bad request, see response body for more information
- `401` — Unauthorized. Supplied credentials are invalid
- `403` — Forbidden. Supplied credentials have no rights
- `404` — Resource not found
- `405` — Used HTTP method is not allowed
- `406` — Not acceptable. The supplied content type in the accept parameter in the header is not supported
- `410` — Indicates that this resource is no longer available for use
- `415` — Unsupported media. The supplied content type in the content-type parameter in the header is not supported
- `422` — Unprocessable entity, see response body for more information
- `429` — Rate limit reached.
- `500` — An internal error occurred.
- `503` — The server is currently unable to handle your request

---

[API](https://skmtc.dev/pay/apis/pay-transaction-gateway-unit-api.md) · [All operations](https://skmtc.dev/pay/apis/pay-transaction-gateway-unit-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/pay/pay-transaction-gateway-unit-api/revisions/2bc260c7bdfc/schema)
