Britive platform release 2026.09.01 is now live in production.

Issue a short-lived token carrying the caller's own permissions

Prev Next
Post
/api/tokens/temp

Returns a short-lived token for the authenticated caller, carrying that caller's own permissions. The token identifies the caller and holds no authorization grants of its own: every request made with it is authorized against the caller's identity at the time of that request. Requires the securityadmin.temptoken.create permission. A temporary token cannot be used to issue another one, and one cannot be issued on behalf of another user.

Security
HTTP
Type bearer
Body parameters
object
Example{ "durationSeconds": 900 }
durationSeconds
integer (int32)

Requested lifetime in seconds. Optional; the tenant's configured lifetime is used when absent.

The schema maximum is the platform ceiling, not the effective limit. The effective limit is the tenant's configured maximum, which is lower, so a request that satisfies this schema can still be rejected with 400. The error names the maximum that applies; read it from there rather than assuming the schema value.

Expiry is enforced to within about a minute, so a lifetime shorter than that is granted as requested but a token already in use may continue to be accepted briefly after it expires.

Minimum1
Maximum86400
Responses
200

Temporary token issued

object
Example{ "accessToken": "EXAMPLE_HEADER.EXAMPLE_PAYLOAD.EXAMPLE_SIGNATURE", "expiresOn": "2026-09-09T21:59:26Z" }
accessToken
string

The token, returned once and not retrievable afterwards.

expiresOn
string (date-time)

When the token expires.

400

The requested duration exceeds the tenant's configured maximum or the 24-hour platform limit, or is otherwise not a valid duration

401

Unauthorized

403

The caller is not permitted to issue a temporary token, presented a temporary token, or is acting on behalf of another user