> ## Documentation Index
> Fetch the complete documentation index at: https://docs.near.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create admin access token (Admin only)

> Creates an access token for admin users with customizable expiration time, IP address, and user agent.
This is typically used by billing services and other automated systems that need access to admin endpoints.

**Security Note:** These tokens can have very long expiration times and should be used with caution.
Store them securely and rotate them regularly.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/admin/access-tokens
openapi: 3.1.0
info:
  title: NEAR AI Cloud API
  description: >-
    NEAR AI Cloud API for private AI model inference and organization
    administration.
  contact:
    name: NEAR AI Team
    email: support@near.ai
  license:
    name: MIT
  version: 1.0.0
servers:
  - url: https://cloud-api.near.ai
    description: NEAR AI Cloud
security:
  - session_token: []
  - api_key: []
tags:
  - name: Chat
    description: Chat completion endpoints for AI model inference
  - name: Images
    description: Image generation endpoints
  - name: Audio
    description: Audio transcription endpoints
  - name: Rerank
    description: Document reranking endpoints
  - name: Score
    description: Text similarity scoring endpoints
  - name: Privacy
    description: Privacy classification (PII span detection) endpoints
  - name: Models
    description: Public model catalog and information
  - name: Responses
    description: >-
      Stateless response inference (`store: false` only). Raw request/response
      content, response items, and history are not persisted. Clients must
      include any prior context in each request. Every successful Responses
      inference makes exactly one Chat Completions call. Only custom `function`
      tools are supported. They are client-managed: Cloud returns
      `function_call` items but never executes them; a later `store: false`
      request replays the individual call (the raw item from output is accepted)
      with its matching `function_call_output`, alongside caller-managed message
      history and the same function tool definitions. The minimal replay path
      also accepts assistant `message` text parts of type `output_text`, but not
      reasoning or arbitrary full `response.output` items. Server-executed tools
      (`web_search`, `web_context_search`, `file_search`, `code_interpreter`,
      `computer`, and remote `mcp`) and image-generation/editing models are
      rejected. The separate `POST /mcp` endpoint continues to expose its
      `web_search` tool independently of Responses; use `/v1/images/*` for image
      generation/editing. Existing completed-response gateway attestation is
      preserved best-effort: when the signature write succeeds, `GET
      /v1/signature/resp_*` retrieves signatures over SHA-256 request/response
      digests, never raw content. Interrupted streams create no `resp_*`
      attestation record or legacy disconnect fallback. Conversations, response
      history, and file input are rejected.
  - name: Organizations
    description: Organization management
  - name: Organization Members
    description: Organization member and invitation management
  - name: Workspaces
    description: Workspace and API key management
  - name: Users
    description: User profile and token management
  - name: Invitations
    description: Token-based invitation handling
  - name: Usage
    description: Usage tracking and billing information
  - name: Reporting
    description: Read-only customer usage reporting
  - name: Billing
    description: Billing costs endpoint (HuggingFace integration)
  - name: Staking Farm
    description: House of Stake farm credit configuration and synchronization
  - name: Health
    description: Health check endpoints
  - name: Attestation
    description: Attestation and verification endpoints
  - name: Gateway
    description: Model gateway integration endpoints
  - name: Admin
    description: Administrative endpoints (admin access required)
  - name: Services
    description: Public platform services (e.g. web_search pricing)
paths:
  /v1/admin/access-tokens:
    post:
      tags:
        - Admin
      summary: Create admin access token (Admin only)
      description: >-
        Creates an access token for admin users with customizable expiration
        time, IP address, and user agent.

        This is typically used by billing services and other automated systems
        that need access to admin endpoints.


        **Security Note:** These tokens can have very long expiration times and
        should be used with caution.

        Store them securely and rotate them regularly.
      operationId: create_admin_access_token
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAdminAccessTokenRequest'
        required: true
      responses:
        '200':
          description: Admin access token created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminAccessTokenResponse'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - session_token: []
components:
  schemas:
    CreateAdminAccessTokenRequest:
      type: object
      description: Admin access token request model
      required:
        - expires_in_hours
        - name
        - reason
      properties:
        expires_in_hours:
          type: integer
          format: int64
          description: Number of hours until the token expires (required)
        name:
          type: string
          description: Name for the token (required)
        reason:
          type: string
          description: Reason for creating the token (required)
    AdminAccessTokenResponse:
      type: object
      description: Admin access token response model
      required:
        - id
        - access_token
        - created_by_user_id
        - created_at
        - expires_at
        - name
        - reason
      properties:
        access_token:
          type: string
        created_at:
          type: string
          format: date-time
        created_by_user_id:
          type: string
        expires_at:
          type: string
          format: date-time
        id:
          type: string
        name:
          type: string
        reason:
          type: string
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
    ErrorDetail:
      type: object
      required:
        - message
        - type
      properties:
        code:
          type:
            - string
            - 'null'
        message:
          type: string
        param:
          type:
            - string
            - 'null'
        type:
          type: string
  securitySchemes:
    session_token:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT access token for user authentication (Authorization: Bearer
        <jwt_token>). Create via POST /users/me/access_tokens.
    api_key:
      type: http
      scheme: bearer
      bearerFormat: api_key
      description: 'API key for programmatic access (Authorization: Bearer sk-<api_key>)'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.