post_api_management_v1_runners_name_tokens
const url = 'https://example.com/api/management/v1/runners/example/tokens';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"overlap_secs":1,"ttl_secs":1}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/management/v1/runners/example/tokens \ --header 'Content-Type: application/json' \ --data '{ "overlap_secs": 1, "ttl_secs": 1 }'Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”Management API runner name
Request Bodyrequired
Section titled “Request Bodyrequired”A request to mint a token.
object
How long the runner’s PREVIOUSLY active tokens stay valid (default 900, max 86400, 0 = revoke them now).
Lifetime of the NEW token in seconds; absent = no expiry.
Examplegenerated
{ "overlap_secs": 1, "ttl_secs": 1}Responses
Section titled “ Responses ”A new token, shown once; older tokens expire after the overlap
A freshly minted token. token is shown exactly once.
object
object
The hub address a runner should dial, when the operator configured one
(SUPACLOUD_RUNNER_HUB_URL).
How many older tokens now expire at the end of the overlap.
Examplegenerated
{ "capabilities": {}, "class": "example", "expires_at": "2026-04-15T12:00:00Z", "hub_url": "example", "labels": [ "example" ], "name": "example", "runner_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "superseded_tokens": 1, "token": "example", "token_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"}Missing runners:write, or not an instance-level token
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}No runner registered under this name
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}