Skip to main content
Issue a short-lived, single-use sponsor token for agent bootstrap under the current organization
Audience: application and coding agent.

Canonical metadata

  • requestId
  • id
  • tokenPrefix
  • scopes
  • expiresAt
  • usedAt

Example request

Example response

Authentication

This is a human organization action. Send a bearer token for a signed-in organization member. API keys are rejected. The sponsor-token secret is returned once; do not log it.

Give this prompt to your agent

Failure posture

  • treat non-2xx responses as contract-aware failures, not free-form errors
  • preserve requestId and traceparent in logs and downstream reports
  • if provenance or freshness metadata is present, return it unchanged so trust is not lost in the handoff