Skip to content

Exchange an API key for a token

POST
/v1/auth/token
curl --request POST \
--url http://localhost:8080/v1/auth/token \
--header 'Content-Type: application/json' \
--data '{ "apiKey": "example" }'

Anonymous, rate-limited per address. Trades an API key (bk_…, issued at POST /v1/api-keys) for a short-lived access token that carries the key’s scopes (intake:write, status:read, evidence:read) instead of roles. There is no refresh token: exchange the key again when the token expires. 401 when the key is unknown or revoked, 400 when it is malformed.

Media typeapplication/json
object
apiKey
string
Examplegenerated
{
"apiKey": "example"
}

OK

Media typeapplication/json
object
accessToken
required
string
expiresAt
required
string format: date-time
scopes
required
Array<string>
Examplegenerated
{
"accessToken": "example",
"expiresAt": "2026-04-15T12:00:00Z",
"scopes": [
"example"
]
}