OrdinateDB

Documentation

product Pre-releaseunwritten sections are marked
POST/v1/auth/service-identities/{id}/tokens

Mint or rotate a service token

operation ID: post_v1_auth_service_identities_by_id_tokens

Overview

Mint or rotate a service token. The authentication API establishes identity and manages the roles, grants, sessions, and service credentials used for authorization.

When to use it

  • Use it when an application needs to mint or rotate a service token.
  • Use it when a client needs to sign in, inspect its identity, or an administrator needs to manage access.

Quick example

Set the base URL and replace generated identifiers or credentials with values from your installation.

cURL

curl --request POST \
  --url "$ORDINATE_URL/v1/auth/service-identities/00000000-0000-4000-8000-000000000001/tokens" \
  --header "Authorization: Bearer $ORDINATE_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{
    "expires_at_ns": 0
  }'

Expected output · 201

One-time plaintext token; it cannot be retrieved again

Example 201 output

{
  "token": "string",
  "token_id": "00000000-0000-4000-8000-000000000001",
  "service_id": "00000000-0000-4000-8000-000000000001",
  "issued_at_ns": 0,
  "expires_at_ns": 0
}

The cURL request sends the smallest contract-derived body and asks OrdinateDB to mint or rotate a service token. The documented 201 response is one-time plaintext token; it cannot be retrieved again.

How it works

OrdinateDB resolves a session or bearer credential to a principal, then evaluates roles, capabilities, and resource scope for each protected operation.

Reference

Required capability
admin
Authorization scope
handler-resolved target

Parameters

NameInRequiredType and constraints
idpathyes
stringformat: uuid

Request body

application/json

commentstringoptional
expires_at_nsintegerrequired

UTC Unix timestamp in nanoseconds

format: int64
rotatebooleanoptional
unknown fields rejected

Example request body

{
  "expires_at_ns": 0
}

Responses

201One-time plaintext token; it cannot be retrieved again

application/json

expires_at_nsintegerrequired

UTC Unix timestamp in nanoseconds

format: int64
issued_at_nsintegerrequired

UTC Unix timestamp in nanoseconds

format: int64
service_idstringrequired
format: uuid
tokenstringrequired

One-time plaintext secret returned only by this mint operation

one-time secret
token_idstringrequired
format: uuid
unknown fields rejected

Example 201 output

{
  "token": "string",
  "token_id": "00000000-0000-4000-8000-000000000001",
  "service_id": "00000000-0000-4000-8000-000000000001",
  "issued_at_ns": 0,
  "expires_at_ns": 0
}
400Invalid token request

application/json

ErrorEnvelope
codestringrequired
correlation_idstringrequired
format: uuid
detailsobjectoptional
errorstringrequired

Example 400 output

{
  "error": "string",
  "code": "account-sealed",
  "correlation_id": "00000000-0000-4000-8000-000000000001"
}
401Authentication required

application/json

ErrorEnvelope
codestringrequired
correlation_idstringrequired
format: uuid
detailsobjectoptional
errorstringrequired

Example 401 output

{
  "error": "string",
  "code": "account-sealed",
  "correlation_id": "00000000-0000-4000-8000-000000000001"
}
403Required capability is not granted

application/json

ErrorEnvelope
codestringrequired
correlation_idstringrequired
format: uuid
detailsobjectoptional
errorstringrequired

Example 403 output

{
  "error": "string",
  "code": "account-sealed",
  "correlation_id": "00000000-0000-4000-8000-000000000001"
}
409Too many active tokens

application/json

ErrorEnvelope
codestringrequired
correlation_idstringrequired
format: uuid
detailsobjectoptional
errorstringrequired

Example 409 output

{
  "error": "string",
  "code": "account-sealed",
  "correlation_id": "00000000-0000-4000-8000-000000000001"
}
503Model database is not configured

application/json

ErrorEnvelope
codestringrequired
correlation_idstringrequired
format: uuid
detailsobjectoptional
errorstringrequired

Example 503 output

{
  "error": "string",
  "code": "account-sealed",
  "correlation_id": "00000000-0000-4000-8000-000000000001"
}

Code examples

These examples are generated from the source contract. Replace the base URL, credentials, identifiers, and minimal generated values for your instance.

JavaScript

const ordinateUrl = "http://localhost:8080";
const token = "<bearer-token>";

const response = await fetch(`${ordinateUrl}/v1/auth/service-identities/00000000-0000-4000-8000-000000000001/tokens`, {
  method: "POST",
  headers: {
    Authorization: `Bearer ${token}`,
    "Content-Type": "application/json"
  },
  body: JSON.stringify({
  "expires_at_ns": 0
})
});

if (!response.ok) {
  throw new Error(`OrdinateDB returned ${response.status}: ${await response.text()}`);
}

const data = await response.json();
console.log(data);