curl --request POST \
--url https://api.mottostreaming.com/iam/auth/v1/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiration_seconds": "<string>",
"resource_scope_keys": [
"<string>"
],
"role_scopes": [
"<string>"
],
"permission_scopes": [
"<string>"
]
}
'import requests
url = "https://api.mottostreaming.com/iam/auth/v1/tokens"
payload = {
"expiration_seconds": "<string>",
"resource_scope_keys": ["<string>"],
"role_scopes": ["<string>"],
"permission_scopes": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expiration_seconds: '<string>',
resource_scope_keys: ['<string>'],
role_scopes: ['<string>'],
permission_scopes: ['<string>']
})
};
fetch('https://api.mottostreaming.com/iam/auth/v1/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.mottostreaming.com/iam/auth/v1/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'expiration_seconds' => '<string>',
'resource_scope_keys' => [
'<string>'
],
'role_scopes' => [
'<string>'
],
'permission_scopes' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.mottostreaming.com/iam/auth/v1/tokens"
payload := strings.NewReader("{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.mottostreaming.com/iam/auth/v1/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.mottostreaming.com/iam/auth/v1/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"token": "<string>"
}{
"code": 123,
"message": "<string>",
"details": [
{
"@type": "<string>"
}
]
}Create token
CreateToken
Creates a new token for the authenticated account. This can be used in various scenarios:
- Creating short-lived tokens with an existing long-lived token for improved security.
- Creating a token that is scoped to a subset of resources that are normally accessible to the account. This is useful for temporary tokens that are used in specific contexts (e.g. CI/CD systems or AI tooling).
curl --request POST \
--url https://api.mottostreaming.com/iam/auth/v1/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiration_seconds": "<string>",
"resource_scope_keys": [
"<string>"
],
"role_scopes": [
"<string>"
],
"permission_scopes": [
"<string>"
]
}
'import requests
url = "https://api.mottostreaming.com/iam/auth/v1/tokens"
payload = {
"expiration_seconds": "<string>",
"resource_scope_keys": ["<string>"],
"role_scopes": ["<string>"],
"permission_scopes": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
expiration_seconds: '<string>',
resource_scope_keys: ['<string>'],
role_scopes: ['<string>'],
permission_scopes: ['<string>']
})
};
fetch('https://api.mottostreaming.com/iam/auth/v1/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.mottostreaming.com/iam/auth/v1/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'expiration_seconds' => '<string>',
'resource_scope_keys' => [
'<string>'
],
'role_scopes' => [
'<string>'
],
'permission_scopes' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.mottostreaming.com/iam/auth/v1/tokens"
payload := strings.NewReader("{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.mottostreaming.com/iam/auth/v1/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.mottostreaming.com/iam/auth/v1/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expiration_seconds\": \"<string>\",\n \"resource_scope_keys\": [\n \"<string>\"\n ],\n \"role_scopes\": [\n \"<string>\"\n ],\n \"permission_scopes\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"token": "<string>"
}{
"code": 123,
"message": "<string>",
"details": [
{
"@type": "<string>"
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
Token expiration in seconds. Minimum is 300 seconds (5 minutes), maximum is 86400*365 seconds (1 year). To create a non-expiring token, set the value to 0.
This property restricts the created token's access only to resources that sit within the hierarchy/hierarchies
defined by resource_scope_keys.
Important: this does not give access to the resources by itself; it is a filter that is applied on top of the existing access
rights of the account for which the token is being created.
This property restricts the created token to the permissions granted by the given roles, identified by their
role ID (e.g. viewer or spiideo_viewer). The roles are treated purely as sets of permissions: the account does
not need to hold these roles itself, and the token can never do more than the account can.
Important: like resource_scope_keys, this is a filter on top of the account's existing access; it does not grant
access by itself. At most 5 roles can be given.
This property restricts the created token to the given permissions (e.g. event.event.get). A scoped wildcard
such as event.* is allowed. When combined with role_scopes, the token is restricted to the intersection of
both; the most restrictive interpretation always wins.
Important: like resource_scope_keys, this is a filter on top of the account's existing access; it does not grant
access by itself. At most 10 permissions can be given.
Response
OK
Created token

