# Create a long-lived API token **POST /auth/generate-token** With `scopes`, mints a scoped automation token (lifetime from `ttlDays` or the configured default, 365 days when unset, never more than 400) and returns the token once with its id, label, scopes and expiry; returns 403 while automation tokens are turned off and 400 for an empty or unsupported scope list. Without `scopes`, mints a legacy full-access token valid for 5 years and returns only `token` and `validTill` (no id); sending `label` or `ttlDays` without `scopes` returns 400. An inactive user gets 401. ## Servers - http://api.example.com: http://api.example.com () ## Authentication methods - Access token ## Parameters ### Body: application/json (object) - **scopes** (array[string]) Automation scopes to grant. Presence of this field mints a scoped automation token; must be non-empty and a subset of the allowed scopes. - **label** (string) Human-readable label for the automation token (e.g. "Zapier – intake"). - **ttlDays** (number) Token lifetime in days (automation tokens only, 1–400). Defaults to the configured automation TTL (~365). ## Responses ### 200 #### Body: application/json (object) - **data** (object) - **statusCode** (number) - **timestamp** (string(date-time)) [Powered by Bump.sh](https://bump.sh)