PCI Tokens
Create token
Create a new token in the PCI DSS scope. See PCI Tokens overview for creation sources (session vs pan) and compliance levels.
POST
Authorizations
JWT bearer token obtained via the OAuth2 client-credentials grant from the platform Authentication API. The token's scopes gate the endpoints it may call, and its audience names the Guardian instance. This is the standard way to authenticate to Guardian.
Body
application/json
- From Session
- From PAN
How many seconds after creation the token expires automatically.
Required range:
1 <= x <= 2592000Example:
3600
Metadata consisting of key-value entries.
- Maximum 20 key-value pairs.
- Maximum 20 characters per key.
- Maximum 80 characters per value.
Example:
Response
Success response
- Session
- Token
Example:
"0f2c8f7e-4d2a-4d1b-9a6e-1c9b2d3e4f50"