Skip to main content

Mint a short-lived access token.

POST 

/access_token

Creates a pair of access credentials — a token and a secret — that a client may use in place of the consumer credentials, and that expires on its own.

The request must be authenticated with consumer credentials. An existing access token cannot mint another one; presenting an access token here fails with forbidden (code 6) Consumer credentials required to create access credentials.

The lifetime is controlled by ttl_seconds in the request body; see CreateAccessTokenRequest for its default and clamping behaviour. The expiry is not echoed back — the response carries only token and secret, so record the lifetime you asked for if you need to know when the token dies.

Request​

Responses​

The new access credentials. Only token and secret are returned.