Docs

Get an end-user token

Get a scoped token for the Embedded SDK or installation API with a full-access API key.

Get a token for one MindCloud end user when your frontend uses the Embedded SDK or your backend calls an endpoint that requires an end-user token.

curl 'https://connect.mindcloud.co/v1/users/<endUserId>/token' \
  -H 'Authorization: Bearer <MINDCLOUD_API_KEY>'

The API returns { "token": "..." }. The API key needs full access because this token can authorize writes. MindCloud checks that the end user belongs to the key's organization. An unknown ID returns 404; a mismatched organization returns 403.

Keep the API key on your server. Give the token only to the signed-in customer it represents, and call setToken(token) before SDK methods. Do not share one end-user token across customers.

The current token signer uses a two-week default expiry. Check the token's actual expiry instead of assuming a fixed duration. The SDK's getTokenExpiration() returns a Date or null; request a new token before expiry and call setToken() again.

Embedded MCP uses your API key with an end-user ID in the URL. It does not use this token.