With scopes, mints a scoped automation token (lifetime from ttlDays or the configured default, 365 days when unset, never more than 400) and returns the token once with its id, label, scopes and expiry; returns 403 while automation tokens are turned off and 400 for an empty or unsupported scope list. Without scopes, mints a legacy full-access token valid for 5 years and returns only token and validTill (no id); sending label or ttlDays without scopes returns 400. An inactive user gets 401.
Body
Required
-
Automation scopes to grant. Presence of this field mints a scoped automation token; must be non-empty and a subset of the allowed scopes.
Values are
cases:create,codes:create, orexports:create. -
Human-readable label for the automation token (e.g. "Zapier – intake").
-
Token lifetime in days (automation tokens only, 1–400). Defaults to the configured automation TTL (~365).
Minimum value is
1, maximum value is400.
curl \
--request POST 'http://api.example.com/auth/generate-token' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"scopes": [
"cases:create"
],
"label": "string",
"ttlDays": 42.0
}'
{
"scopes": [
"cases:create"
],
"label": "string",
"ttlDays": 42.0
}
{
"data": {
"createdAt": "2026-01-15T14:30:00.000Z",
"updatedAt": "2026-01-15T14:30:00.000Z",
"id": "507f1f77bcf86cd799439011",
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI2NWExYjJjMyJ9.c2lnbmF0dXJl",
"validTill": "2027-01-15T10:15:00.000Z",
"scopes": [
"cases:create"
],
"label": "Intake sync"
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}