Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Mint a session token

POST/api/v1/mcp/configs/{mcp_config_id}/tokens

Mints a short-lived JWT that represents a user identifier across the connected accounts associated with an MCP configuration. The supplied identifier becomes the token's sub claim; the token's aud claim is the MCP server URL bound to the configuration. Claims also carry the MCP configuration ID (mcp_cfg) and the list of resolved connected-account IDs (ca_ids). Use this operation to issue a single credential an MCP server can present on the user's behalf when calling provider tools. The mint fails if any connection mapped to the configuration has no active connected account for the identifier.

Authorization

Authorization: Bearer $TOKEN, an access token from the client credentials grant. See Authentication.

Path parameters

mcp_config_idstringrequired
Unique ID of the MCP configuration whose connections back the token. The configuration must exist in the caller's environment.

Body

identifierstringrequired
Your app's ID for the user, the same value you used when the user connected.
expirystring
How long the token lasts, in seconds with an s suffix, such as 1800s. Between 60s and 86400s (24 hours). Defaults to 3600s.

Response 200

expires_atstring
When the token expires: the time it was minted plus expiry.
tokenstring
The session token, a signed JWT. Its sub claim is the identifier and its aud claim is the MCP server URL it works at. Send it as Authorization: Bearer <token> from the MCP client.

Errors

Every error has the same body: code, message and details. See Errors and rate limits.

400Invalid request - mcp_config_id or identifier is missing or malformed, expiry is outside the 60s-24h window, the MCP configuration has no connections, or a connection has no active connected account for the supplied identifier
404Not Found - no MCP configuration exists with the supplied ID in the caller's environment

Used in