Create an API token for a service account

Mints an API token for the service account and returns its accessToken once. The token
inherits the service account's permissions as they stand at creation; there is no per-token
scoping. Returns 409 when the service account already has a token of the same name, and
422 at the cap of 10 tokens.

dryRun=true checks the name bounds only, then returns a preview without creating anything.
It does not verify that the service account exists, that the name is unused, or that the
account is under the token cap, so a dry run can succeed where the real create then returns
404, 409 or 422. Requires the serviceAccountCreator permission.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
length ≥ 1

ID of the service account that owns the token, as returned in the id field by the service account list and create operations.

Query Params
boolean
Defaults to false

If true, validates the request and returns the would-be result without applying it. The response then carries the X-Dry-Run header.

Body Params

The API token to create.

Fields of a new API token.

string
required
length between 1 and 100

Name, unique among the service account's tokens. Leading or trailing whitespace returns 400.

date-time

When the token should stop authenticating. Omit to let the server set the default expiry.

Headers
string
required
length between 1 and 255

Client-generated key (UUID v4 or ULID recommended). Retrying with the same key and request returns the stored response instead of repeating the operation; the key is kept for 24 hours.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json