Skip to content
Select themeSelect language

post_api_management_v1_runners_name_tokens

POST
/api/management/v1/runners/{name}/tokens
curl --request POST \
--url https://example.com/api/management/v1/runners/example/tokens \
--header 'Content-Type: application/json' \
--data '{ "overlap_secs": 1, "ttl_secs": 1 }'
name
required
string

Management API runner name

Media typeapplication/json

A request to mint a token.

object
overlap_secs

How long the runner’s PREVIOUSLY active tokens stay valid (default 900, max 86400, 0 = revoke them now).

integer | null format: int64
ttl_secs

Lifetime of the NEW token in seconds; absent = no expiry.

integer | null format: int64
Examplegenerated
{
"overlap_secs": 1,
"ttl_secs": 1
}

A new token, shown once; older tokens expire after the overlap

Media typeapplication/json

A freshly minted token. token is shown exactly once.

object
capabilities
required
object
class
required
string
expires_at
required
string | null format: date-time
hub_url
required

The hub address a runner should dial, when the operator configured one (SUPACLOUD_RUNNER_HUB_URL).

string | null
labels
required
Array<string>
name
required
string
runner_id
required
string format: uuid
superseded_tokens
required

How many older tokens now expire at the end of the overlap.

integer format: int64
token
required
string
token_id
required
string format: uuid
Examplegenerated
{
"capabilities": {},
"class": "example",
"expires_at": "2026-04-15T12:00:00Z",
"hub_url": "example",
"labels": [
"example"
],
"name": "example",
"runner_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"superseded_tokens": 1,
"token": "example",
"token_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"
}

Missing runners:write, or not an instance-level token

Media typeapplication/json

The canonical JSON body of every error response — the single source of truth the frontend binds to. Every AppError serializes as this exact shape, and the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is what the frontend error schema is generated from, so there is no hand-written error schema on either end.

object
code
required

Machine-readable, stable error code.

string
Allowed values: not_found unauthorized forbidden license_required license_expired bad_request unprocessable precondition_failed conflict method_not_allowed rate_limited too_many_requests quota_exceeded database_error docker_error vault_error internal_error
details
One of:
null
error
required

Human-readable message (the server’s English text; the client may localize by code).

string
Example
{
"code": "not_found"
}

No runner registered under this name

Media typeapplication/json

The canonical JSON body of every error response — the single source of truth the frontend binds to. Every AppError serializes as this exact shape, and the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is what the frontend error schema is generated from, so there is no hand-written error schema on either end.

object
code
required

Machine-readable, stable error code.

string
Allowed values: not_found unauthorized forbidden license_required license_expired bad_request unprocessable precondition_failed conflict method_not_allowed rate_limited too_many_requests quota_exceeded database_error docker_error vault_error internal_error
details
One of:
null
error
required

Human-readable message (the server’s English text; the client may localize by code).

string
Example
{
"code": "not_found"
}