# Make a CI token

Source: https://immiscible.fly.dev/docs/api/post-v1-cli-tokens

`POST /v1/cli/tokens`

A CLI token for a machine, shown once: it acts for the same person in the same workspace, with the presenting token's scopes or fewer, and expires in `expiresInDays` (1 to 90, default 90). What `immiscible token create` calls.

## Authentication

CLI token. A token (`imc_...`) the developer CLI gets by signing in through the browser (`immiscible login`, the OAuth device grant), sent as `Authorization: Bearer`. It acts for one person in one workspace: it reads agents and status, and registers an agent with a rule from the same purposes as the console's "Add an agent". It never approves anything or changes an existing rule. Every use re-checks the person's membership and the workspace's sign-in rules; it lasts 90 days and ends from the console's sessions.

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/v1/cli/tokens" \
  -H "authorization: Bearer $IMMISCIBLE_TOKEN" \
  -H "content-type: application/json" \
  -d '{
    "name": "ci",
    "readOnly": true,
    "expiresInDays": 30
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/v1/cli/tokens', {
  method: 'POST',
  headers: {
    authorization: `Bearer ${process.env.IMMISCIBLE_TOKEN}`,
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    name: 'ci',
    readOnly: true,
    expiresInDays: 30,
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.post(
    "https://immiscible.fly.dev/v1/cli/tokens",
    headers={
        "authorization": f"Bearer {os.environ['IMMISCIBLE_TOKEN']}",
        "content-type": "application/json",
    },
    json={
        "name": "ci",
        "readOnly": True,
        "expiresInDays": 30,
    },
)
print(res.status_code, res.json())
```

## Response

```json
{
  "id": "clt_ef9160fc75835d11",
  "name": "github-actions",
  "token": "imc_...",
  "scopes": [
    "agents:read"
  ],
  "expiresAt": "2027-01-04T12:48:18.393Z",
  "workspaceId": "ws_fa833074ebeb45e8",
  "note": "This is the only time the token is shown."
}
```
