API reference · Trust Fabric
Mint a short-lived agent delegation token
POST /fabric/identity/agent-tokens
Last reviewed 2026-10-02
POST /fabric/identity/agent-tokens
Delegates to the agent-id service, which owns the signing key. This endpoint exists so agent delegation lives in the same Identity namespace as everything else, not so the Fabric can re-implement token signing.
Request body
AgentTokenRequest (required)
| Field | Type | Meaning |
|---|---|---|
agent_id required | string | min length 1 · max length 255 |
scopes required | array of string | min items 1 |
ttl_seconds | integer | min 1.0 · max 3600.0 · default 900 |
chain | array of string |
Responses
| Status | Meaning | Body |
|---|---|---|
200 | Successful Response | JSON |
422 | Validation Error | HTTPValidationError |
401 | No key, or a key that is not valid | JSON detail |
429 | Rate limit for your plan reached; retry after the Retry-After seconds | JSON detail |
Try it
This call changes data in the account the key belongs to.
The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.
Code
curl -sS -X POST 'https://cainstudio.online/fabric/identity/agent-tokens' \
-H "X-API-Key: $CAIN_API_KEY" \
-H 'Content-Type: application/json' \
-d '{"agent_id": "agent-id", "scopes": ["scopes"], "ttl_seconds": 900}'import json, os, urllib.request
req = urllib.request.Request('https://cainstudio.online/fabric/identity/agent-tokens', method='POST',
headers={"X-API-Key": os.environ["CAIN_API_KEY"], "Content-Type": "application/json"},
data=json.dumps({
"agent_id": "agent-id",
"scopes": [
"scopes"
],
"ttl_seconds": 900
}).encode())
with urllib.request.urlopen(req, timeout=60) as r:
print(r.status, json.load(r))const res = await fetch("https://cainstudio.online/fabric/identity/agent-tokens", {
method: "POST",
headers: {
"X-API-Key": process.env.CAIN_API_KEY!,
"Content-Type": "application/json",
},
body: JSON.stringify({
"agent_id": "agent-id",
"scopes": [
"scopes"
],
"ttl_seconds": 900
}),
});
console.log(res.status, await res.json());Schemas used
AgentTokenRequest · HTTPValidationError · ValidationError
← Who has read this tenant's evidence · all 79 Trust Fabric calls · Verify an agent delegation token →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem