> ## Documentation Index
> Fetch the complete documentation index at: https://docs.quivr.thevibecompany.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue a source-scoped push token

> Requires connectors:admin on the instance's Organization and Corpus. Issue a random bearer token for this instance's instance_token routes only (Plugin API 0.12). The secret is shown once in this response with Cache-Control no-store; only its SHA-256 hash and display metadata are stored. Issuance is not replayable. If the response is lost, list tokens, revoke the lost token and issue another. Disabled instances refuse issuance with 409 connector_disabled. No request body is needed.



## OpenAPI

````yaml /openapi.yaml post /v0/connectors/{connector_id}/tokens
openapi: 3.1.0
info:
  title: Quivr HTTP API
  version: 0.0.0-draft
  description: >-
    Every endpoint of the Quivr v0 HTTP API. Send an API key as a bearer token;
    the key decides the Organization, the actions and the Corpora a request may
    reach.
servers: []
security:
  - ApiKey: []
paths:
  /v0/connectors/{connector_id}/tokens:
    parameters:
      - name: connector_id
        in: path
        required: true
        schema:
          type: string
          minLength: 1
    post:
      tags:
        - Connectors
      summary: Issue a source-scoped push token
      description: >-
        Requires connectors:admin on the instance's Organization and Corpus.
        Issue a random bearer token for this instance's instance_token routes
        only (Plugin API 0.12). The secret is shown once in this response with
        Cache-Control no-store; only its SHA-256 hash and display metadata are
        stored. Issuance is not replayable. If the response is lost, list
        tokens, revoke the lost token and issue another. Disabled instances
        refuse issuance with 409 connector_disabled. No request body is needed.
      operationId: createConnectorToken
      responses:
        '201':
          description: New token with its one-time bearer secret.
          headers:
            Cache-Control:
              schema:
                type: string
                enum:
                  - no-store
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectorTokenCreated'
        default:
          description: >-
            JSON Error envelope; 401 unauthenticated, 403 without admin
            permission, 404 out of scope, 409 disabled, 503 unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ConnectorTokenCreated:
      type: object
      additionalProperties: false
      required:
        - token
        - secret
      properties:
        token:
          $ref: '#/components/schemas/ConnectorToken'
        secret:
          type: string
          description: >-
            One-time bearer secret; never persisted or returned by metadata
            reads.
    Error:
      type: object
      additionalProperties: false
      properties:
        code:
          type: string
          minLength: 1
        message:
          type: string
          minLength: 1
        retryable:
          type: boolean
        field:
          type: string
          minLength: 1
          description: >-
            JSON Pointer (RFC 6901) to the request member that caused a 422,
            when known (for example /config/url or /credential/secret/token on
            connector commands).
        resync_url:
          type: string
          format: uri-reference
      required:
        - code
        - message
        - retryable
    ConnectorToken:
      type: object
      additionalProperties: false
      required:
        - token_id
        - prefix
        - created_at
      properties:
        token_id:
          type: string
        prefix:
          type: string
          description: Display prefix only; cannot authenticate.
        created_at:
          type: string
          format: date-time
        rotated_at:
          type: string
          format: date-time
        revoked_at:
          type: string
          format: date-time
        valid_until:
          type: string
          format: date-time
          description: >-
            Exclusive expiry of an old token after rotation; absent for an
            unrotated token.
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        API key, not necessarily a JWT. Server derives Organization, permitted
        actions and Corpus scope; every resource access is authorized.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.