# Mint SDK Token

`POST /api/sdk/token`

Create a single-use token for one of your call-center agents. Call this from **your backend** (see the [embed guide](/api-docs/sdk)). The browser talks only to your site; your server talks to us.

Requires a Bearer API token (from [Authentication](/api-docs/authentication) / dashboard **API Tokens**) and the **call-center** permission.

Return this JSON to the browser unchanged. The [widget](/api-docs/sdk/widget) uses it to connect. Do not store or reuse the token.

## Request Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| agent_id | integer | Yes | Numeric id of a call-center agent that belongs to your account. The agent must be active and approved. Get ids from [List Agents](/api-docs/call-center/agents). |

## Request Example

```bash
curl -X POST https://api.awajdigital.com/api/sdk/token \
  -H "Authorization: Bearer your_api_token_here" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "agent_id": 42
  }'
```

```javascript
// Do not call this URL from the page with your API token.
// The browser should POST to your own login-protected route instead
// (see the embed guide). That route calls this endpoint on your server.
const response = await fetch('/api/amarvoice-token', {
  method: 'POST',
  headers: {
    'Accept': 'application/json',
    'Content-Type': 'application/json'
  },
  credentials: 'include'
});

const data = await response.json();
console.log(data);
```

```javascript
// Node.js with axios
const axios = require('axios');

async function mintSdkToken(agentId) {
  try {
    const response = await axios.post('https://api.awajdigital.com/api/sdk/token', {
      agent_id: agentId
    }, {
      headers: {
        'Authorization': 'Bearer your_api_token_here',
        'Accept': 'application/json',
        'Content-Type': 'application/json'
      }
    });

    console.log(response.data);
  } catch (error) {
    console.error('Error:', error.response?.data || error.message);
  }
}

mintSdkToken(42);
```

```python
# Python with requests
import requests

def mint_sdk_token(agent_id):
    url = 'https://api.awajdigital.com/api/sdk/token'
    headers = {
        'Authorization': 'Bearer your_api_token_here',
        'Accept': 'application/json',
        'Content-Type': 'application/json'
    }
    data = {
        'agent_id': agent_id
    }

    try:
        response = requests.post(url, json=data, headers=headers)
        print(response.json())
    except requests.exceptions.RequestException as e:
        print(f'Error: {e}')

mint_sdk_token(42)
```

```php
<?php
// PHP with cURL
$url = 'https://api.awajdigital.com/api/sdk/token';
$token = 'your_api_token_here';

$data = [
    'agent_id' => 42
];

$ch = curl_init($url);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data));
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    'Authorization: Bearer ' . $token,
    'Accept: application/json',
    'Content-Type: application/json'
]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

$response = curl_exec($ch);
curl_close($ch);

$result = json_decode($response, true);
print_r($result);
?>
```

## Success Response Example

```json
{
  "token": "avt_…",
  "expires_in": 300,
  "expires_at": "2026-09-06T12:05:00.000+06:00",
  "session_url": "https://api.awajdigital.com/api/sdk/session"
}
```

| Field | Type | Description |
| --- | --- | --- |
| token | string | Single-use token. Your page should not request this itself — proxy this endpoint and let the SDK call your proxy via `tokenUrl`. |
| expires_in | integer | Lifetime in seconds. |
| expires_at | string | ISO 8601 expiry. |
| session_url | string | URL the widget uses to start the call session. Forward this JSON as-is. |

## Error Responses

| Status | Code | Description |
| --- | --- | --- |
| 401 | — | Missing or invalid access token |
| 403 | — | Account does not have the call-center permission |
| 403 | `agent_inactive` | Agent exists but is not active |
| 403 | `agent_not_approved` | Agent exists but is not approved |
| 404 | `agent_not_found` | Agent does not exist or belongs to another account |
| 422 | — | Validation failed (`agent_id` missing or not a positive integer) |
| 429 | — | Too many requests |

```json
{
  "error": "agent not found",
  "code": "agent_not_found"
}
```