---
title: "CreateNewToken adds a token to a service account"
method: POST
path: "/serviceaccounts/{serviceAccountId}/tokens"
tags: ["service_accounts"]
---

# CreateNewToken adds a token to a service account

`POST /serviceaccounts/{serviceAccountId}/tokens`

Required permissions (See note in the [introduction](https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/#service-account-api) for an explanation):
action: `serviceaccounts:write` scope: `serviceaccounts:id:1` (single service account)

## Path parameters

- `serviceAccountId` integer, required

## Request body

- AddServiceAccountTokenCommand
  - `name` string
  - `secondsToLive` integer

## Response `200`

(empty)

- NewApiKeyResult
  - `id` integer
  - `key` string
  - `name` string

## Other responses

- `400` — BadRequestError is returned when the request is invalid and it cannot be processed.
- `401` — UnauthorizedError is returned when the request is not authenticated.
- `403` — ForbiddenError is returned if the user/token has insufficient permissions to access the requested resource.
- `404` — NotFoundError is returned when the requested resource was not found.
- `409` — ConflictError
- `500` — InternalServerError is a general error indicating something went wrong internally.

---

[API](https://skmtc.net/grafana/apis/http-api.md) · [All operations](https://skmtc.net/grafana/apis/http-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/grafana/http-api/revisions/df55ba1718ba/schema)
