Mint a session token
Mints a short-lived JWT that represents a user identifier across the connected accounts associated with an MCP configuration. The supplied identifier becomes the token's sub claim; the token's aud claim is the MCP server URL bound to the configuration. Claims also carry the MCP configuration ID (mcp_cfg) and the list of resolved connected-account IDs (ca_ids). Use this operation to issue a single credential an MCP server can present on the user's behalf when calling provider tools. The mint fails if any connection mapped to the configuration has no active connected account for the identifier.
Authorization
Authorization: Bearer $TOKEN, an access token from the client credentials grant. See Authentication.
Path parameters
mcp_config_idstringrequiredBody
identifierstringrequiredexpirystrings suffix, such as 1800s. Between 60s and 86400s (24 hours). Defaults to 3600s.scalekit_client.actions.mcp.create_session_token
Create a short-lived session token for a user to access an MCP server. The token is scoped to a specific MCP configuration and end-user. Pass it as a Bearer token in the Authorization header when making requests to the MCP server URL associated with the config.
scalekit_client.actions.mcp.create_session_token( mcp_config_id: str, identifier: str, expiry: Optional[timedelta] = None,) -> CreateMcpSessionTokenResponseParameters
mcp_config_idstrrequired"cfg_01abc123".identifierstrrequiredexpiryOptional[timedelta]timedelta. When omitted, the server-side default TTL is applied (typically 1 hour). Example values: timedelta(minutes=30) — 30-minute token; timedelta(hours=8) — 8-hour token (work-day session); timedelta(days=1) — 24-hour tokenReturns CreateMcpSessionTokenResponse: The session token, a signed JWT, and expires_at, when it expires (UTC).
From scalekit-sdk-python 2.19.1.
scalekit.actions.mcp.createSessionToken
Mints a session token for one user against one configuration. The server URL is static; this token is what carries user identity. Mint a fresh one before every agent run and never reuse one across runs. Set the expiry longer than the run is expected to take.
scalekit.actions.mcp.createSessionToken( params: { mcpConfigId: string; identifier: string; expirySeconds?: number; },): Promise<CreateMcpSessionTokenResponse>Parameters
mcpConfigIdstringrequiredidentifierstringrequiredexpirySecondsnumberReturns Promise<CreateMcpSessionTokenResponse>.
From @scalekit-sdk/node 2.18.0.
Response 200
expires_atstringexpiry.tokenstringsub claim is the identifier and its aud claim is the MCP server URL it works at. Send it as Authorization: Bearer <token> from the MCP client.Errors
Every error has the same body: code, message and details. See Errors and rate limits.
400Invalid request - mcp_config_id or identifier is missing or malformed, expiry is outside the 60s-24h window, the MCP configuration has no connections, or a connection has no active connected account for the supplied identifier404Not Found - no MCP configuration exists with the supplied ID in the caller's environment