curl --request POST \
--url https://api.sidenet.ai/v1/token \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"user_id": "user_4821",
"group_id": "grp_84f20c19",
"tools_auth": {
"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63": {
"credentials": {
"token": "the end user's CRM token"
}
}
}
}
EOFimport requests
url = "https://api.sidenet.ai/v1/token"
payload = {
"user_id": "user_4821",
"group_id": "grp_84f20c19",
"tools_auth": { "8d3b1a75-6c02-4e59-b84f-27a9d5e10c63": { "credentials": { "token": "the end user's CRM token" } } }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
user_id: 'user_4821',
group_id: 'grp_84f20c19',
tools_auth: {
'8d3b1a75-6c02-4e59-b84f-27a9d5e10c63': {credentials: {token: 'the end user\'s CRM token'}}
}
})
};
fetch('https://api.sidenet.ai/v1/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sidenet.ai/v1/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'user_id' => 'user_4821',
'group_id' => 'grp_84f20c19',
'tools_auth' => [
'8d3b1a75-6c02-4e59-b84f-27a9d5e10c63' => [
'credentials' => [
'token' => 'the end user\'s CRM token'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sidenet.ai/v1/token"
payload := strings.NewReader("{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sidenet.ai/v1/token")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sidenet.ai/v1/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"access_token": "<string>",
"refresh_token": "<string>",
"token_type": "Bearer",
"expires_in": 123,
"refresh_expires_in": 123
}Mint session token
Exchanges your organization API key for a short-lived access token scoped to one end user, safe to hand to a browser.
Call this from your backend only — it takes the user id, optionally the group id, and optionally the user’s tool credentials. An omitted group_id falls back to the user’s current group, then the organization’s Default group. Display names live on the update routes (PATCH /v1/users/{userId} / PATCH /v1/groups/{groupId}), not here.
Session tokens are scoped to the chat runtime. Endpoints that modify your organization — agents, workflows, prompt blocks, tool providers — require the API key from your backend.
curl --request POST \
--url https://api.sidenet.ai/v1/token \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data @- <<EOF
{
"user_id": "user_4821",
"group_id": "grp_84f20c19",
"tools_auth": {
"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63": {
"credentials": {
"token": "the end user's CRM token"
}
}
}
}
EOFimport requests
url = "https://api.sidenet.ai/v1/token"
payload = {
"user_id": "user_4821",
"group_id": "grp_84f20c19",
"tools_auth": { "8d3b1a75-6c02-4e59-b84f-27a9d5e10c63": { "credentials": { "token": "the end user's CRM token" } } }
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
user_id: 'user_4821',
group_id: 'grp_84f20c19',
tools_auth: {
'8d3b1a75-6c02-4e59-b84f-27a9d5e10c63': {credentials: {token: 'the end user\'s CRM token'}}
}
})
};
fetch('https://api.sidenet.ai/v1/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.sidenet.ai/v1/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'user_id' => 'user_4821',
'group_id' => 'grp_84f20c19',
'tools_auth' => [
'8d3b1a75-6c02-4e59-b84f-27a9d5e10c63' => [
'credentials' => [
'token' => 'the end user\'s CRM token'
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.sidenet.ai/v1/token"
payload := strings.NewReader("{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.sidenet.ai/v1/token")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.sidenet.ai/v1/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"user_id\": \"user_4821\",\n \"group_id\": \"grp_84f20c19\",\n \"tools_auth\": {\n \"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63\": {\n \"credentials\": {\n \"token\": \"the end user's CRM token\"\n }\n }\n }\n}"
response = http.request(request)
puts response.read_body{
"access_token": "<string>",
"refresh_token": "<string>",
"token_type": "Bearer",
"expires_in": 123,
"refresh_expires_in": 123
}Authorizations
Organization API key, generated in studio.sidenet.ai. Backend only — never in a browser.
Body
Your stable id for the end user. Becomes their identity on every call this token makes. An id that hasn't been seen before CREATES the user — name them via PATCH /v1/users/{userId}, or pre-create with POST /v1/users.
"user_4821"
The group this session belongs to — today the unit billing and spend caps attach to. An id that hasn't been seen before CREATES the group, with the default spend cap — name and cap it via PATCH /v1/groups/{groupId}, or pre-create with POST /v1/groups. Optional: when omitted, the session uses the user's current group (set by a previous mint, chat call, or PATCH /v1/users/{userId}), falling back to the organization's Default group. Send it explicitly if you bill per team — the fallback is silent.
"grp_84f20c19"
Per-provider credentials, keyed by tool provider id — { "PROVIDER_ID": { "credentials": { … }, "base_url"?: "…" } }. Stored on the user (encrypted at rest) and injected server-side on every call they make — sessions, workflow runs and schedules alike. Only the providers you send are replaced. Never returned, logged, or cached.
{
"8d3b1a75-6c02-4e59-b84f-27a9d5e10c63": {
"credentials": { "token": "the end user's CRM token" }
}
}
Response
Session created