Exchange an API key for a token
POST
/v1/auth/token
const url = 'http://localhost:8080/v1/auth/token';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"apiKey":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:8080/v1/auth/token \ --header 'Content-Type: application/json' \ --data '{ "apiKey": "example" }'Anonymous, rate-limited per address. Trades an API key (bk_…, issued at POST /v1/api-keys) for a short-lived access token that carries the key’s scopes (intake:write, status:read, evidence:read) instead of roles. There is no refresh token: exchange the key again when the token expires. 401 when the key is unknown or revoked, 400 when it is malformed.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
apiKey
string
Examplegenerated
{ "apiKey": "example"}Responses
Section titled “Responses”OK
Media typeapplication/json
object
accessToken
required
string
expiresAt
required
string format: date-time
scopes
required
Array<string>
Examplegenerated
{ "accessToken": "example", "expiresAt": "2026-04-15T12:00:00Z", "scopes": [ "example" ]}