---
title: "Create a service token"
method: POST
path: "/tokens"
tags: ["tokens"]
---

# Create a service token

`POST /tokens`

Create a service token for machine-to-machine authentication. Accepts API key or bearer token. Optionally apply restrictions.

## Request body

- CreateTokenRequest
  - `policy` Constraint[] — Constraint objects to restrict the token. Cannot be combined with profileSlug. Each constraint may include a `ttl` field (max 24 hours). Default TTL is 1 hour. Maximum is 24 hours.
    - `namespaces` union — Restrict token to specific namespaces.
      - string
      - string[]
    - `resources` union — Restrict token to specific resource types.
      - 'connections' | 'servers' | 'namespaces' | 'skills'
      - string[]
    - `operations` union — Restrict token to specific operations.
      - 'read' | 'write' | 'execute'
      - string[]
    - `metadata` union — Metadata key-value pairs for fine-grained access control. When an array is provided, each object is evaluated as an OR condition (any must match). Within a single object, all key-value pairs must match (AND). For example, [{"userId": "alice"}, {"team": "backend"}] allows access if userId is alice OR team is backend.
      - object
      - object[]
    - `ttl` union — TTL as seconds or duration string ("1h", "30m", "20s").
      - string
      - number
  - `profileSlug` string — Profile slug for legacy token minting. Cannot be combined with policy.

## Response `200`

Token created successfully

- CreateTokenResponse
  - `token` string, required — The signed service token.
  - `expiresAt` string, required — ISO 8601 timestamp when the token expires.

## Other responses

- `400` — Bad request (invalid parameters)
- `401` — Unauthorized (missing or invalid credentials)
- `403` — Forbidden

## Changes

- **2026-02-02** `6547bf9b8910` — 2 warning, 2 info
  - removed the request property `allow`
  - removed the request property `ttlSeconds`
  - added the new optional request property `policy`
  - removed the non-success response with the status `404`
- **2026-01-27** `12e546828dc5` — 1 warning, 1 info
  - removed the request property `allow/rpc`
  - added the new optional request property `allow/mcp`

[Change history](https://skmtc.dev/smithery-ai/apis/smithery-platform-api/changes/tokens/post.md)

---

[API](https://skmtc.dev/smithery-ai/apis/smithery-platform-api.md) · [All operations](https://skmtc.dev/smithery-ai/apis/smithery-platform-api/llms.txt) · [OpenAPI document](https://skmtc.dev/smithery-ai/apis/smithery-platform-api/revisions/9d53933ba12e?raw)
