> ## Documentation Index
> Fetch the complete documentation index at: https://docs.keystoneos.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a session token

> Requires the `sessions:write` scope (as an M2M scope or a user permission).

Exchange M2M credentials for a scoped, short-lived session token that can be used in frontend widgets. Session tokens cannot create other session tokens.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/sessions
openapi: 3.1.0
info:
  title: Keystone API
  description: Settlement orchestration API for tokenized Real-World Assets (RWAs).
  version: 0.9.0
  x-keystone-api-contract-version: 0.9.0
  x-keystone-source-revision: c094c5ec38de81d550cde98e6366efaac99cffea
servers:
  - url: https://api-staging.keystoneos.xyz
    description: Staging (sandbox)
  - url: https://api.keystoneos.xyz
    description: Production
security:
  - bearerAuth: []
tags:
  - name: health
    description: Health and version checks.
  - name: platforms
    description: Register and manage your platform profile.
  - name: environments
    description: Manage platform environments (sandbox, production).
  - name: settlement-templates
    description: View and manage settlement templates.
  - name: settlements
    description: Initiate, monitor, and manage settlements.
  - name: sessions
    description: Create and manage browser-safe session tokens for frontend widgets.
  - name: instructions
    description: Submit and manage settlement instructions.
  - name: invitations
    description: Invite team members to your platform.
  - name: members
    description: Manage platform team members and roles.
  - name: webhooks
    description: Configure webhook endpoints for real-time event notifications.
  - name: security
    description: IP allowlisting and API access controls.
  - name: activity
    description: Audit trail of platform actions.
  - name: dashboard
    description: Dashboard metrics and statistics.
  - name: callbacks
    description: Provider callback handlers (internal).
  - name: alchemy-webhooks
    description: Alchemy blockchain event webhooks (internal).
  - name: chains
    description: Supported blockchain networks for settlement.
  - name: admin
    description: KeyStone internal administration endpoints.
  - name: admin-platforms
    description: Admin platform management.
  - name: admin-settlements
    description: Admin settlement oversight and intervention.
  - name: admin-compliance
    description: Admin compliance check management.
  - name: admin-activity
    description: Admin system-wide activity logs.
  - name: admin-webhooks
    description: Admin webhook diagnostics.
  - name: internal
    description: Keystone-internal worker endpoints.
  - name: internal-compliance
    description: Internal compliance engine endpoints.
paths:
  /v1/sessions:
    post:
      tags:
        - sessions
      summary: Create a session token
      description: >-
        Requires the `sessions:write` scope (as an M2M scope or a user
        permission).


        Exchange M2M credentials for a scoped, short-lived session token that
        can be used in frontend widgets. Session tokens cannot create other
        session tokens.
      operationId: create_session_v1_sessions_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SessionTokenCreate'
        required: true
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionTokenRead'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: >-
            Too many credentials issued on this route:
            RATE_LIMIT_CREDENTIAL_ISSUANCE. Retry-After reports when the window
            frees a slot.
          headers:
            Retry-After:
              schema:
                type: string
            X-RateLimit-Limit:
              schema:
                type: string
            X-RateLimit-Remaining:
              schema:
                type: string
            X-RateLimit-Reset:
              schema:
                type: string
components:
  schemas:
    SessionTokenCreate:
      properties:
        scopes:
          items:
            type: string
          type: array
          minItems: 1
          title: Scopes
          description: Permissions granted to this session token.
        expires_in:
          type: integer
          maximum: 86400
          minimum: 60
          title: Expires In
          description: Token TTL in seconds (60 to 86400).
          default: 3600
        settlement_ids:
          anyOf:
            - items:
                type: string
                format: uuid
              type: array
              minItems: 1
            - type: 'null'
          title: Settlement Ids
          description: >-
            Restrict token to specific settlement IDs. Omit the field entirely
            for an unrestricted token. An empty list is rejected: a caller that
            computed an empty permitted set is asking for a token that reaches
            nothing, and silently minting an environment-wide token there would
            invert the intent.
        metadata:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Metadata
          description: >-
            Platform-provided context for audit trail (e.g., user_id,
            user_email).
      type: object
      required:
        - scopes
      title: SessionTokenCreate
      description: Request body for creating a new session token.
    SessionTokenRead:
      properties:
        session_token:
          type: string
          title: Session Token
          description: The signed JWT to pass to the frontend KeystoneProvider.
          x-keystone-credential: true
        expires_at:
          type: string
          format: date-time
          title: Expires At
          description: When the token expires (UTC).
        token_id:
          type: string
          format: uuid
          title: Token Id
          description: Token ID for revocation.
      type: object
      required:
        - session_token
        - expires_at
        - token_id
      title: SessionTokenRead
      description: Response after creating a session token.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
        code:
          type: string
          enum:
            - VALIDATION_ERROR
          title: Code
        docs_url:
          type: string
          title: Docs Url
          examples:
            - https://docs.keystoneos.xyz/guides/error-codes#validation-error
      type: object
      title: HTTPValidationError
      required:
        - detail
        - code
        - docs_url
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Auth0 JWT access token. See
        [Authentication](/getting-started/authentication) for details.

````