As an Organization Admin, create a short-lived session token for a user in your organization.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Authenticate with an Organization Admin User API key, sent in the skyfire-api-key header. Keys belonging to callers whose organization role is ADMIN are accepted; a MEMBER key, or any Agent API key, is rejected with 401.
The user identified by userId must belong to your organization. A user that does not exist, or that belongs to another organization, is reported as 404.
Your organization must have a representative user, and the target user must have a Skyfire login identity. If either is missing, the call returns 400.
Response
The response body is the session token itself, returned as a bare JSON string rather than an object (Content-Type: application/json). The body includes the surrounding double quotes, so parse it as JSON, or strip the quotes if you read it as plain text.
Token lifetime
The session token expires 5 minutes after it is created. The lifetime is fixed and cannot be changed in the request. Create the token immediately before you need it, and request a new one when it expires.
Treat the session token as a credential. It acts as the user whose
userIdyou supplied. Do not log it or share it.
Validation notes
userIdis required and must be a valid UUID.- Calling this endpoint again does not revoke earlier tokens. Each one stays valid until its own 5 minutes are up.

