Skip to main content
POST
Open a Service Token Issuance Request (Maker step of maker/checker)

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

service
string
required

Workspace Service ID

Body

application/json

CreateWorkspaceServiceAccessTokenRequestData

name
string
required

The display name of the access token

Maximum string length: 55
Example:

"Helpdesk Ticket Automation"

description
string
required

A detailed description of the access token

Example:

"Production environment token managed by HashiCorp Vault."

justification
string
required

The business justification for issuing this credential. Required for compliance evidence (SOX 404 maker/checker, SOC2 CC6.1). Recorded verbatim in the audit log; visible to auditors

Required string length: 30 - 500
Example:

"Quarterly access review automation; replaces token rotated 2026-04-01."

expires_at
string<date-time> | null

The expiration date of this access token. Capped to a configurable maximum (default 90 days) by the post-rules validator

Response

id
string
required
workspace_service_id
string
required
requested_by
string
required
approved_by
string | null
required
name
string
required
description
string
required
justification
string
required
expires_at
string<date-time> | null
required
approved_at
string<date-time> | null
required
rejected_at
string<date-time> | null
required
issued_workspace_token_id
string | null
required
created_at
string<date-time> | null
required
updated_at
string<date-time> | null
required
deleted_at
string<date-time> | null
required
state
enum<string>
required
Available options:
pending,
approved,
rejected,
expired