# POST /v1/servers/{id}/tokens

Create a key for a server

Creates another live key for the server and answers its value once; it is never shown again. Every key of a server has the same rights. A server holds at most two live keys: the one in use and the one being rotated in.

Takes an account key (`ak_…`) as a bearer token. TypeScript: `account.servers.tokens.create(serverId, { name })`. Python: `account.servers.tokens.create(server_id, name=...)`.

## Parameters

- `id` (path, required, string (uuid)): The server id.

## Request body

- `name` (string (at least 1, at most 100 characters), required): 1 to 100 characters.

Example:

```json
{
  "name": "Invoicing system"
}
```

## Responses

### 201 The new key, its value shown this once.

- `tokenId` (string (uuid), required)
- `name` (string, required): The name given at creation, for people to tell keys apart.
- `prefix` (string, required): The first characters of the key, to match it with a value in hand.
- `createdAt` (string (date-time), required)
- `revokedAt` (string (date-time) or null, required)
- `token` (string, required): The key itself, shown this once.

Example:

```json
{
  "tokenId": "3b0c9e2f-6d4a-4e8b-8a1c-9f2d7e6c5b40",
  "name": "Invoicing system",
  "prefix": "sk_a1b2c3d4e5",
  "createdAt": "2026-09-20T12:00:00.000Z",
  "revokedAt": null,
  "token": "sk_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v"
}
```

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `invalid_request` | 400 | The body, the query or a header does not match what the route takes. |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
| `not_found` | 404 | No such server of this account. |
| `token_limit` | 409 | The server or the account already holds two live keys: one in use and one to rotate to. Revoke one before creating another. |

### `invalid_request`

- `issues` (array of object): One entry per invalid field; absent when a header is wrong.
  - `path` (string, required): The field, dotted, such as to.0.email; empty when the whole body is wrong.
  - `message` (string, required)

Example:

```json
{
  "error": "invalid_request",
  "message": "The request is invalid: to.0: Invalid email address",
  "issues": [
    {
      "path": "to.0",
      "message": "Invalid email address"
    }
  ]
}
```

### `token_limit`

- `max` (integer, required): Live keys the owner may hold at once.

Example:

```json
{
  "error": "token_limit",
  "message": "The server may hold at most 2 live keys; revoke one before creating another.",
  "max": 2
}
```
