/v1/auth/service-identities/{id}/tokensMint or rotate a service token
operation ID: post_v1_auth_service_identities_by_id_tokens
Overview
Mint or rotate a service token. The authentication API establishes identity and manages the roles, grants, sessions, and service credentials used for authorization.
When to use it
- Use it when an application needs to mint or rotate a service token.
- Use it when a client needs to sign in, inspect its identity, or an administrator needs to manage access.
Quick example
Set the base URL and replace generated identifiers or credentials with values from your installation.
cURL
curl --request POST \
--url "$ORDINATE_URL/v1/auth/service-identities/00000000-0000-4000-8000-000000000001/tokens" \
--header "Authorization: Bearer $ORDINATE_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"expires_at_ns": 0
}'Expected output · 201
One-time plaintext token; it cannot be retrieved again
Example 201 output
{
"token": "string",
"token_id": "00000000-0000-4000-8000-000000000001",
"service_id": "00000000-0000-4000-8000-000000000001",
"issued_at_ns": 0,
"expires_at_ns": 0
}The cURL request sends the smallest contract-derived body and asks OrdinateDB to mint or rotate a service token. The documented 201 response is one-time plaintext token; it cannot be retrieved again.
How it works
OrdinateDB resolves a session or bearer credential to a principal, then evaluates roles, capabilities, and resource scope for each protected operation.
Reference
- Required capability
- admin
- Authorization scope
- handler-resolved target
Parameters
| Name | In | Required | Type and constraints |
|---|---|---|---|
id | path | yes | stringformat: uuid |
Request body
application/json
commentstringoptionalexpires_at_nsintegerrequiredUTC Unix timestamp in nanoseconds
format: int64rotatebooleanoptional
Example request body
{
"expires_at_ns": 0
}Responses
201One-time plaintext token; it cannot be retrieved again
application/json
expires_at_nsintegerrequiredUTC Unix timestamp in nanoseconds
format: int64issued_at_nsintegerrequiredUTC Unix timestamp in nanoseconds
format: int64service_idstringrequired- format: uuid
tokenstringrequiredOne-time plaintext secret returned only by this mint operation
one-time secrettoken_idstringrequired- format: uuid
Example 201 output
{
"token": "string",
"token_id": "00000000-0000-4000-8000-000000000001",
"service_id": "00000000-0000-4000-8000-000000000001",
"issued_at_ns": 0,
"expires_at_ns": 0
}400Invalid token request
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 400 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}401Authentication required
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 401 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}403Required capability is not granted
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 403 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}409Too many active tokens
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 409 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}503Model database is not configured
application/json
ErrorEnvelope
codestringrequiredcorrelation_idstringrequired- format: uuid
detailsobjectoptionalerrorstringrequired
Example 503 output
{
"error": "string",
"code": "account-sealed",
"correlation_id": "00000000-0000-4000-8000-000000000001"
}Code examples
These examples are generated from the source contract. Replace the base URL, credentials, identifiers, and minimal generated values for your instance.
JavaScript
const ordinateUrl = "http://localhost:8080";
const token = "<bearer-token>";
const response = await fetch(`${ordinateUrl}/v1/auth/service-identities/00000000-0000-4000-8000-000000000001/tokens`, {
method: "POST",
headers: {
Authorization: `Bearer ${token}`,
"Content-Type": "application/json"
},
body: JSON.stringify({
"expires_at_ns": 0
})
});
if (!response.ok) {
throw new Error(`OrdinateDB returned ${response.status}: ${await response.text()}`);
}
const data = await response.json();
console.log(data);Related topics
- Authentication guide — Understand the prerequisite concepts and transport behavior for this operation.
- REST endpoint index — Find other operations in Authentication.