---
title: "Get authentication token for a customer"
method: POST
path: "/customers/actions/auth-token"
tags: ["Customers actions"]
---

# Get authentication token for a customer

`POST /customers/actions/auth-token`

Returns an authentication token for a specific customer. Another application that uses the CareCloud API can use this token to verify the customer's identity or authenticate the customer.

Typical uses include initiating customer sign-in in another application or portal, or passing a customer's identity to an in-app browser for a different application.

⚠️ Endpoint is available only in the Enterprise interface.

## Headers

- `Accept-Language` string

## Request body

- object
  - `customer_id` string, required — The unique ID of the customer. [GET /customers](https://carecloud.readme.io/reference/getcustomers)
  - `external_application_id` string, required — ID of the destination external application. Please provide the destination external application ID, not the token-issuing external application ID. Need a destination external application ID? Please contact your CareCloud administrator.
  - `token_type` 1 | 2, required — Sets which token type should be generated. *Possible values: 1 - alphanumeric, 2 - numeric*

## Response `200`

OK

- object
  - `data` object
    - `authentication_token` string — Authentication token that allows the customer to log in to another external application.
    - `token_request_id` string — The parameter specifies the request that caused the token to be created. If two customers generated an authentication token at the same time and in the same application, the token_request_id parameter represents additional verification to identify the correct token.
    - `valid_to` string — Date and time of the token validity. *(YYYY-MM-DD HH:MM:SS)*

## Other responses

- `400` — Bad input parameter. The response body's `error.error_data.invalid_params[]` array lists the parameters that caused the failure, each carrying a `reason` code. See the `BadRequestErrorBody` schema for the generic reason taxonomy. Operations with domain-specific business rules document additional reasons at the operation level.
- `401` — The client has invalid credentials or auth token.
- `403` — The client does not exist or the client tried to access an unauthorized property or resource.
- `404` — The resource was not found.
- `405` — The resource does not support the specified HTTP method.
- `429` — Too many requests - more than the resource limit.
- `500` — Server is not working as expected.
- `503` — Temporary state when the service is temporarily unavailable, overloaded or there is a maintenance window.

---

[API](https://skmtc.net/crmcarecloud/apis/rest-api-reference.md) · [All operations](https://skmtc.net/crmcarecloud/apis/rest-api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/crmcarecloud/rest-api-reference/revisions/329c06dbf8d9/schema)
