---
title: "Create a JWT"
method: POST
path: "/auth/issue-token"
tags: ["Authentication"]
---

# Create a JWT

`POST /auth/issue-token`

Returns a JWT for authenticating client-side SDKs such as the Inbox. You supply the scope and an expires_in duration, both required.

## Request body

- object
  - `scope` string, required — Available scopes: - `user_id:<user-id>` - Defines which user the token will be scoped to. Multiple can be listed if needed. Ex `user_id:pigeon user_id:bluebird`. - `read:messages` - Read messages. - `read:user-tokens` - Read user push tokens. - `write:user-tokens` - Write user push tokens. - `read:brands[:<brand_id>]` - Read brands, optionally restricted to a specific brand_id. Examples `read:brands`, `read:brands:my_brand`. - `write:brands[:<brand_id>]` - Write brands, optionally restricted to a specific brand_id. Examples `write:brands`, `write:brands:my_brand`. - `inbox:read:messages` - Read inbox messages. - `inbox:write:events` - Write inbox events, such as mark message as read. - `read:preferences` - Read user preferences. - `write:preferences` - Write user preferences. Example: `user_id:user123 write:user-tokens inbox:read:messages inbox:write:events read:preferences write:preferences read:brands`
  - `expires_in` string, required — Duration for token expiration. Accepts various time formats: - "2 hours" - 2 hours from now - "1d" - 1 day - "3 days" - 3 days - "10h" - 10 hours - "2.5 hrs" - 2.5 hours - "1m" - 1 minute - "5s" - 5 seconds - "1y" - 1 year

## Response `200`

- IssueTokenResponse
  - `token` string, required

## Changes

- **2025-10-15** `e67d02739533` — 2 info
  - api tag `Authentication` added
  - api tag `AuthTokens` removed
- **2025-10-07** `7143ea51f307` — 14 breaking, 1 info
  - removed the enum value `inbox:read:messages` of the request property `scope`
  - removed the enum value `inbox:write:event` of the request property `scope`
  - removed the enum value `inbox:write:events` of the request property `scope`
  - removed the enum value `inbox:write:messages` of the request property `scope`
  - …11 more

[Change history](https://skmtc.dev/trycourier/apis/courier/changes/auth/issue-token/post.md)

---

[API](https://skmtc.dev/trycourier/apis/courier.md) · [All operations](https://skmtc.dev/trycourier/apis/courier/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/trycourier/courier/revisions/cb8586034158/schema)
