> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apsio.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a project token

> A token that reads this project, and writes only with the scopes chosen, for 7, 30, 90, 365 days (90 by default). Owners and admins, from a console session only. The token is in this answer only: Apsio keeps its id, never the token.



## OpenAPI

````yaml /api-reference/openapi.json post /orgs/{orgId}/projects/{projectId}/tokens
openapi: 3.1.0
info:
  title: Apsio API
  version: 0.1.0
  description: >-
    Read API v0: your projects, release health and comparisons, missing symbols,
    issues, sessions, vitals, cohort comparisons, performance (app start,
    screens, hangs, MetricKit) and network endpoints and traces for one project.
    Authenticate with a project token as a bearer token, with an OAuth access
    token from Apsio's authorization server (MCP clients), or, from the console,
    with the session cookie of a member of the project's organization.
servers:
  - url: https://api.apsio.io/v1
security: []
paths:
  /orgs/{orgId}/projects/{projectId}/tokens:
    post:
      summary: Create a project token
      description: >-
        A token that reads this project, and writes only with the scopes chosen,
        for 7, 30, 90, 365 days (90 by default). Owners and admins, from a
        console session only. The token is in this answer only: Apsio keeps its
        id, never the token.
      parameters:
        - schema:
            type: string
            pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
            example: 0192f3a4-0000-7000-8000-00000000a001
          required: true
          name: orgId
          in: path
        - schema:
            type: string
            pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
            example: 0192f3a4-0000-7000-8000-00000000a001
          required: true
          name: projectId
          in: path
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 100
                scopes:
                  type: array
                  items:
                    type: string
                    enum:
                      - dashboards:write
                      - issues:write
                    description: >-
                      A write scope besides reading: dashboards:write (create
                      and edit dashboards, never delete) or issues:write (change
                      issue states and assignees).
                  maxItems: 2
                  default: []
                days:
                  anyOf:
                    - type: number
                      enum:
                        - 7
                    - type: number
                      enum:
                        - 30
                    - type: number
                      enum:
                        - 90
                    - type: number
                      enum:
                        - 365
                  default: 90
                  description: How long the token lasts, in days.
              required:
                - name
      responses:
        '201':
          description: The token, once
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NewProjectToken'
      security:
        - session: []
components:
  schemas:
    NewProjectToken:
      allOf:
        - $ref: '#/components/schemas/ProjectToken'
        - type: object
          properties:
            token:
              type: string
              description: >-
                The token itself (apsio_pt_v0…), shown this once. Keep it as
                APSIO_TOKEN; Apsio cannot show it again.
          required:
            - token
    ProjectToken:
      type: object
      properties:
        id:
          type: string
          description: The token's id (its jti); never the token.
        project_id:
          type: string
        name:
          type: string
        scopes:
          type: array
          items:
            type: string
            enum:
              - dashboards:write
              - issues:write
            description: >-
              A write scope besides reading: dashboards:write (create and edit
              dashboards, never delete) or issues:write (change issue states and
              assignees).
          description: 'Write scopes; empty: the token only reads.'
        created_by:
          type:
            - string
            - 'null'
        created_by_name:
          type: string
          description: Empty for a token Apsio staff made, or a user since erased.
        created_at:
          type: string
        expires_at:
          type: string
        last_used_at:
          type:
            - string
            - 'null'
          description: Written at most every 5 minutes.
      required:
        - id
        - project_id
        - name
        - scopes
        - created_by
        - created_by_name
        - created_at
        - expires_at
        - last_used_at
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: apsio_session
      description: >-
        The console session, set by /v1/auth/callback (`__Host-apsio_session`
        when host-only).

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.