Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Mint a session token for a connection

POST/api/v1/mcp/connections/{key_id}/tokens

Mints a short-lived token for one user that an MCP client sends to one connection's MCP server, at <environment URL>/mcp/v3/connections/{key_id}, without a Virtual MCP server. The token's sub claim is the identifier and its aud claim is that server URL, so the token works only there. Use it when an agent needs the tools of exactly one connection.

Authorization

Authorization: Bearer $TOKEN, an access token from the client credentials grant. See Authentication.

Path parameters

key_idstringrequired
The connection name, as shown in AgentKit > Connections. It's also the last path segment of the connection's MCP server URL.

Body

identifierstringrequired
Your app's ID for the user, the same value you used when the user connected.
expirystring
How long the token lasts, in seconds with an s suffix, such as 1800s. Between 60s and 86400s (24 hours). Defaults to 3600s.

Response 200

expires_atstring
When the token expires: the time it was minted plus expiry.
tokenstring
The session token, a signed JWT. Its sub claim is the identifier and its aud claim is the MCP server URL it works at. Send it as Authorization: Bearer <token> from the MCP client.

Errors

Every error has the same body: code, message and details. See Errors and rate limits.

400Invalid request - key_id or identifier is missing or malformed, expiry is outside the 60s-24h window, or the connection isn't an AgentKit connection. When the user has no active account on the connection yet, Scalekit creates a pending one and still returns a token, so the user can authorize from the MCP client.
404Not found - no active connection with this name exists in the environment.