Skip to main content
POST
Mint client token

Authorizations

Authorization
string
header
required

Send your team API key or project token as Authorization: Bearer <token>. The credential must have the required permissions. Project tokens can access only their own project.

Body

application/json
ephemeralId
string
required

Your identifier for the browser or mobile user receiving this token.

Value constraints

Minimum string length: 1
session
string

ID of the session this token can access. Provide exactly one of session or customer.

Value constraints

Minimum string length: 1
customer
string<uuid>

Polymorfa Customer ID. The token covers the numbers this Customer owns when it is minted, and only while the Customer still owns each one. Provide exactly one of session or customer. Requires the customers:read scope and enrollment in the Customer-scoped client tokens beta.

Value constraints

allow
enum<string>[]

Actions this Customer-scoped token may use. Each request is also limited by the session's client rules. Omit to use the client rules alone. Only valid with customer.

Allowed item values

Value constraints

Required array length: 1 - 7 elements
Available options:
send_message,
send_reaction,
send_typing,
send_seen,
read_presence,
subscribe_presence,
read_contact
ttlSeconds
integer

Token lifetime in seconds. Must be at least 1 and within the maximum allowed lifetime. Omit to use that maximum.

Response

Token minted

success
enum<boolean>
required

Whether the request succeeded.

Allowed values

Available options:
true
data
object
required

Structured data carried by this object.