> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue Token Response

> This API generates a content of a successful token response that the authorization server implementation returns to the client application.

<Accordion title="Full description" defaultOpen={false}>
  This API is supposed to be called from within the implementation of the token endpoint of the service
  in order to generate a successful response to the client application.
  The description of the `/auth/token` API describes the timing when this API should be called. See
  the description for the case of `action=PASSWORD`.
  The response from `/auth/token/issue` API has some parameters. Among them, it is `action` parameter
  that the authorization server implementation should check first because it denotes the next action
  that the authorization server implementation should take. According to the value of `action`, the
  authorization server implementation must take the steps described below.

  ## INTERNAL\_SERVER\_ERROR

  When the value of `action` is `INTERNAL_SERVER_ERROR`, it means that the request from the authorization
  server implementation was wrong or that an error occurred in Authlete.
  In either case, from the viewpoint of the client application, it is an error on the server side.
  Therefore, the service implementation should generate a response to the client application with
  HTTP status of "500 Internal Server Error".
  The value of `responseContent` is a JSON string which describes the error, so it can be used
  as the entity body of the response.

  ***

  The following illustrates the response which the service implementation should generate and return
  to the client application.

  ```
  HTTP/1.1 500 Internal Server Error
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```

  The endpoint implementation may return another different response to the client application
  since "500 Internal Server Error" is not required by OAuth 2.0.

  ## OK

  When the value of `action` is `OK`, it means that Authlete's `/auth/token/issue` API successfully
  generated an access token.
  The HTTP status of the response returned to the client application must be "200 OK" and the content
  type must be`application/json`.
  The value of `responseContent` is a JSON string which contains an access token, so it can be used
  as the entity body of the response.

  ***

  The following illustrates the response which the service implementation must generate and return
  to the client application.

  ```
  HTTP/1.1 200 OK
  Content-Type: application/json
  Cache-Control: no-store
  Pragma: no-cache
  &#123;responseContent&#125;
  ```
</Accordion>


## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/auth/token/issue
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/auth/token/issue:
    post:
      tags:
        - Token Endpoint
      summary: Issue Token Response
      description: >
        This API generates a content of a successful token response that the
        authorization server implementation

        returns to the client application.
      operationId: auth_token_issue_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/token_issue_request'
            example:
              ticket: p7SXQ9JFjng7KFOZdCMBKcoR3ift7B54l1LGIgQXqEM
              subject: john
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/token_issue_request'
      responses:
        '200':
          description: Token issued successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/token_issue_response'
              example:
                resultCode: A054001
                resultMessage: >-
                  [A054001] The token request (grant_type=password) was
                  processed successfully.
                accessToken: OthV6TlZ2pPUtlBBvBSGFYzSdgVy87SSIPz2Zjwi-m0
                accessTokenDuration: 3600
                accessTokenExpiresAt: 1640331371876
                action: OK
                clientAttributes:
                  - key: attribute1-key
                    value: attribute1-value
                  - key: attribute2-key
                    value: attribute2-value
                clientId: 26478243745571
                clientIdAlias: my-client
                clientIdAliasUsed: false
                refreshToken: ICPN0-sG3BH4szqiNqaFHZrWUGt7e0zaPuhys3ejQow
                refreshTokenDuration: 3600
                refreshTokenExpiresAt: 1640331371876
                responseContent: >-
                  {\"access_token\":\"OthV6TlZ2pPUtlBBvBSGFYzSdgVy87SSIPz2Zjwi-m0\",\"refresh_token\":\"ICPN0-sG3BH4szqiNqaFHZrWUGt7e0zaPuhys3ejQow\",\"scope\":null,\"token_type\":\"Bearer\",\"expires_in\":3600}
                serviceAttributes:
                  - key: attribute1-key
                    value: attribute1-value
                  - key: attribute2-key
                    value: attribute2-value
                subject: john
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.token.issue({
                serviceId: "<id>",
                tokenIssueRequest: {
                  ticket: "p7SXQ9JFjng7KFOZdCMBKcoR3ift7B54l1LGIgQXqEM",
                  subject: "john",
                },
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: >-
            require 'authlete_ruby_sdk'


            Models = ::Authlete::Models

            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            res = s.tokens.issue_response(service_id: '<id>',
            token_issue_request: Models::Components::TokenIssueRequest.new(
              ticket: 'p7SXQ9JFjng7KFOZdCMBKcoR3ift7B54l1LGIgQXqEM',
              subject: 'john'
            ))


            unless res.token_issue_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"github.com/authlete/authlete-go-sdk/models/components\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Token.Issue(ctx, \"<id>\", components.TokenIssueRequest{\n        Ticket: \"p7SXQ9JFjng7KFOZdCMBKcoR3ift7B54l1LGIgQXqEM\",\n        Subject: \"john\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.TokenIssueResponse != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v -X POST
            https://us.authlete.com/api/21653835348762/auth/token/issue \

            -H 'Content-Type: application/json' \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F' \

            -d '{ "ticket": "p7SXQ9JFjng7KFOZdCMBKcoR3ift7B54l1LGIgQXqEM",
            "subject": "john" }'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            TokenIssueRequest req = new TokenIssueRequest()
            req.setTicket("83BNqKIhGMyrkvop_7jQjv2Z1612LNdGSQKkvkrf47c");

            api.tokenIssue(req);
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            req = TokenIssueRequest()
            req.ticket = '83BNqKIhGMyrkvop_7jQjv2Z1612LNdGSQKkvkrf47c'

            api.tokenIssue(req)
components:
  schemas:
    token_issue_request:
      type: object
      required:
        - ticket
        - subject
      properties:
        ticket:
          type: string
          description: |
            The ticket issued from Authlete `/auth/token` API.
        subject:
          type: string
          description: |
            The subject (= unique identifier) of the authenticated user.
        properties:
          type: array
          items:
            $ref: '#/components/schemas/property'
          description: >
            Extra properties to associate with a newly created access token.
            Note that properties parameter is accepted only

            when `Content-Type` of the request is `application/json`, so don't
            use `application/x-www-form-urlencoded`

            if you want to specify properties.
        jwtAtClaims:
          type: string
          description: >
            Additional claims that are added to the payload part of the JWT
            access token.
        accessToken:
          type: string
          description: >
            The representation of an access token that may be issued as a result
            of the Authlete API call.
        accessTokenDuration:
          type: integer
          format: int64
          description: >
            The duration (in seconds) of the access token that may be issued as
            a result of the Authlete

            API call.


            When this request parameter holds a positive integer, it is used as
            the duration of the access

            token in. In other cases, this request parameter is ignored.
        refreshTokenDuration:
          type: integer
          format: int64
          description: >
            The duration (in seconds) of the refresh token that may be issued as
            a result of the Authlete

            API call.


            When this request parameter holds a positive integer, it is used as
            the duration of the refresh

            token in. In other cases, this request parameter is ignored.
    token_issue_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - INTERNAL_SERVER_ERROR
            - OK
          description: >-
            The next action that the authorization server implementation should
            take.
        responseContent:
          type: string
          description: >
            The content that the authorization server implementation is to
            return to the client application.

            Its format is JSON.
        accessToken:
          type: string
          description: >-
            The newly issued access token. This parameter is a non-null value
            only when the value of `action` parameter is `OK`.
        accessTokenExpiresAt:
          type: integer
          format: int64
          description: >
            The datetime at which the newly issued access token will expire.

            The value is represented in milliseconds since the Unix epoch
            (1970-01-01).
        accessTokenDuration:
          type: integer
          format: int64
          description: The duration of the newly issued access token in seconds.
        refreshToken:
          type: string
          description: >
            The refresh token. This parameter is a non-null value only when
            `action` is `OK` and the service supports the refresh token flow.

            If `refreshTokenKept` is set to `false`, a new refresh token is
            issued and the old refresh token used in the refresh token flow

            is invalidated. On the contrary, if `refreshTokenKept` is set to
            `true`, the refresh token itself is not refreshed.
        refreshTokenExpiresAt:
          type: integer
          format: int64
          description: >
            The datetime at which the newly issued refresh token will expire.

            The value is represented in milliseconds since the Unix epoch
            (1970-01-01).
        refreshTokenDuration:
          type: integer
          format: int64
          description: The duration of the newly issued refresh token in seconds.
        clientId:
          type: integer
          format: int64
          description: The client ID.
        clientIdAlias:
          type: string
          description: >
            The client ID alias. If the client did not have an alias, this
            parameter is `null`.
        clientIdAliasUsed:
          type: boolean
          description: >
            The flag which indicates whether the client ID alias was used when
            the token request was made.

            `true` if the client ID alias was used when the token request was
            made.
        subject:
          type: string
          description: >
            The subject (= resource owner's ID) of the access token.

            Even if an access token has been issued by calling `/api/auth/token`
            API, this parameter is `null` if the flow of the token request was

            [Client Credentials
            Flow](https://datatracker.ietf.org/doc/html/rfc6749#section-4.4)
            (`grant_type=client_credentials`) because it means

            the access token is not associated with any specific end-user.
        scopes:
          type: array
          items:
            type: string
          description: The scopes covered by the access token.
        properties:
          type: array
          items:
            $ref: '#/components/schemas/property'
          description: >
            The extra properties associated with the access token.

            This parameter is `null` when no extra property is associated with
            the issued access token.
        jwtAccessToken:
          type: string
          description: >
            The newly issued access token in JWT format. If the authorization
            server is configured to issue JWT-based access tokens

            (= if the service's `accessTokenSignAlg` value is a non-null value),
            a JWT-based access token is issued along with the

            original random-string one.
        accessTokenResources:
          type: array
          items:
            type: string
          description: >
            The target resources of the access token being issued. See "Resource
            Indicators for OAuth 2.0" for details.
        authorizationDetails:
          $ref: '#/components/schemas/authz_details'
        serviceAttributes:
          type: array
          items:
            $ref: '#/components/schemas/pair'
          description: >
            The attributes of this service that the client application belongs
            to.
        clientAttributes:
          type: array
          items:
            $ref: '#/components/schemas/pair'
          description: |
            The attributes of the client.
        clientEntityId:
          type: string
          description: |
            The entity ID of the client.
        clientEntityIdUsed:
          type: boolean
          description: >
            Flag which indicates whether the entity ID of the client was used
            when the request for the access token was made.
        refreshTokenScopes:
          type: array
          items:
            type: string
          description: |
            The scopes associated with the refresh token. May be null.
        metadataDocumentLocation:
          type: string
          format: uri
          description: >
            The location of the client's metadata document that was used to
            resolve client metadata.


            This property is set when client metadata was retrieved via the
            [OAuth Client ID Metadata
            Document](https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/)
            (CIMD) mechanism.
        metadataDocumentUsed:
          type: boolean
          description: >
            Flag indicating whether a metadata document was used to resolve
            client metadata for this request.


            When `true`, the client metadata was retrieved via the CIMD
            mechanism rather than from the Authlete database.
    property:
      type: object
      properties:
        key:
          type: string
          description: The key part.
        value:
          type: string
          description: The value part.
        hidden:
          type: boolean
          description: >
            The flag to indicate whether this property hidden from or visible to
            client applications.

            If `true`, this property is hidden from client applications.
            Otherwise, this property is visible to client applications.
    authz_details:
      type: object
      description: >
        The authorization details. This represents the value of the
        `authorization_details`

        request parameter in the preceding device authorization request which is
        defined in

        "OAuth 2.0 Rich Authorization Requests".
      properties:
        elements:
          type: array
          items:
            $ref: '#/components/schemas/authorization_details_element'
          description: |
            Elements of this authorization details.
    pair:
      type: object
      properties:
        key:
          type: string
          description: The key part.
        value:
          type: string
          description: The value part.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
    authorization_details_element:
      type: object
      required:
        - type
      properties:
        type:
          type: string
          description: >
            The type of this element.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"The type of
            authorization data as a string.

            This field MAY define which other elements are allowed in the
            request. This element is REQUIRED."_


            This property is always NOT `null`.
        locations:
          type: array
          items:
            type: string
          description: >
            The resources and/or resource servers. This property may be `null`.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the location of

            the resource or resource server. This is typically composed of
            URIs."_


            This property may be `null`.
        actions:
          type: array
          items:
            type: string
          description: >
            The actions.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the kinds of actions

            to be taken at the resource. The values of the strings are
            determined by the API being protected."_


            This property may be `null`.
        dataTypes:
          type: array
          items:
            type: string
          description: >
            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the kinds of data being requested

            from the resource."_


            This property may be `null`.
        identifier:
          type: string
          description: >
            The identifier of a specific resource.

            From _"OAuth 2.0 Rich Authorization Requests"_: _"A string
            identifier indicating a specific resource available at the API."_


            This property may be `null`.
        privileges:
          type: array
          items:
            type: string
          description: >
            The types or levels of privilege.

            From "OAuth 2.0 Rich Authorization Requests": _"An array of strings
            representing the types or

            levels of privilege being requested at the resource."_


            This property may be `null`.
        otherFields:
          type: string
          description: >
            The RAR request in the JSON format excluding the pre-defined
            attributes such as `type` and `locations`.

            The content and semantics are specific to the deployment and the use
            case implemented.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````