---
title: "Mint a publish token for one of your sources"
method: POST
path: "/me/publish-tokens"
tags: ["Account"]
---

# Mint a publish token for one of your sources

`POST /me/publish-tokens`

Signed-in session only: the web cookie session, or the session token from `releases login` as a Bearer. API keys, machine tokens and OAuth access tokens are refused. Cookie requests must come from the web origin. Mints a `relk_` token bound to one source, usable ONLY on that source's `POST …/releases/batch` route (e.g. from the publish-changelog GitHub Action). Requires a verified ownership claim on the source's organization; the token stops working if the claim or the source goes away. The plaintext token is returned once. At most 5 active publish tokens per source per user.

## Request body

- object
  - `sourceId` string, required
  - `name` string, required

## Response `201`

Created publish token, including the one-time secret

- object
  - `token` string, required
  - `id` string, required
  - `sourceId` string, required
  - `name` string, required
  - `createdAt` string, required

## Other responses

- `400` — Invalid body
- `401` — Sign-in required
- `403` — No verified ownership claim on the source's organization
- `404` — Lane disabled, or the source doesn't exist
- `409` — Maximum active publish tokens for this source reached

## Changes

- **2026-09-24** `8e4dbcfac6d7` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/releases/apis/releases-api/changes/me/publish-tokens/post.md)

---

[API](https://skmtc.dev/releases/apis/releases-api.md) · [All operations](https://skmtc.dev/releases/apis/releases-api/llms.txt) · [OpenAPI document](https://skmtc.dev/releases/apis/releases-api/revisions/099eb92e3137?raw)
