> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lendflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Personal Access Token

> Generates a new personal access token with the specified name, abilities
(scopes), expiration time, and description. Returns the token resource
with the plain text token that should be securely stored by the client
(it will only be shown once).



## OpenAPI

````yaml /openapi.yaml post /api/access_tokens
openapi: 3.0.3
info:
  title: Lendflow API docs
  description: ''
  version: 1.0.0
servers:
  - url: https://api.lendflow.com
security:
  - default: []
tags:
  - name: Authentication
    description: >-

      Lendflow uses API Bearer Tokens to permit access to our API. You can
      register for a new Lendflow API key on our <a style="color:blue;"
      href="https://app.lendflow.com/login">client portal</a> in less than 60
      seconds. The Bearer Token needs to be included in all API requests made to
      the API Service in the following form: <div
      id="auth-example">Authorization: Bearer [YOUR_TOKEN]</div><div
      id="auth-reminder"><div id="edge-green"></div><div
      id="auth-reminder-text">You must replace [YOUR_TOKEN] with your personal
      API key.</div></div>
  - name: Access Tokens
    description: |-

      Create and manage the personal access tokens used to authenticate API
      requests.
  - name: Workflow Management
    description: |-

      Create applications and manage them through every stage of their workflow,
      from intake through decision.
  - name: Documents
    description: |-

      Upload, retrieve, and manage the files attached to an application.
  - name: Placements
    description: |-

      Submit applications to lenders and manage each placement through its
      lifecycle.
  - name: Offers
    description: |-

      Create and manage offers on an application, from initial terms through
      funding.
  - name: Smartviews
    description: |-

      Save and manage reusable application filters that organize your pipeline.
  - name: Workflow Templates
    description: |-

      Browse the workflow templates available for creating applications.
  - name: Consent Templates
    description: |-

      Manage the consent documents presented to applicants for signature.
  - name: Offer Templates
    description: |-

      Manage the templates that define the structure and fields of your offers.
  - name: Data Orchestration
    description: |-

      Run data orchestration templates against applications and review their
      execution logs.
  - name: Attributes
    description: |-

      Define computed attributes and evaluate them against your applications.
  - name: Scorecards
    description: |-

      Run scorecards and scorecard groups against applications and retrieve
      their results.
  - name: Entity Profiles
    description: |-

      Manage the reusable business and individual profiles shared across
      applications.
  - name: Organization
    description: |-

      Manage the users in your organization.
  - name: Metadata
    description: |-

      Attach custom key-value data to your applications and files.
paths:
  /api/access_tokens:
    post:
      tags:
        - Access Tokens
      summary: Create Personal Access Token
      description: |-
        Generates a new personal access token with the specified name, abilities
        (scopes), expiration time, and description. Returns the token resource
        with the plain text token that should be securely stored by the client
        (it will only be shown once).
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: Access token name. Must not be greater than 255 characters.
                  example: b
                description:
                  type: string
                  description: >-
                    Access token description. Must not be greater than 1000
                    characters.
                  example: Et animi quos velit et fugiat.
                  nullable: true
                expires_at:
                  type: string
                  description: >-
                    Access token expiration data. Must be a valid date. Must be
                    a date after <code>now</code>.
                  example: '2052-11-01'
                  nullable: true
                abilities:
                  type: array
                  description: ''
                  example:
                    - client:view
                  items:
                    type: string
                    enum:
                      - ai-agent-session:create
                      - ai-agent-session:view
                      - application:assign-role
                      - application:create
                      - application:delete
                      - application:duplicate
                      - application:enrich
                      - application:manually-sign-application
                      - application:move-stage
                      - application:sign-application
                      - application:update
                      - application:view
                      - application:view-any
                      - attribute:create
                      - attribute:delete
                      - attribute:evaluate
                      - attribute:update
                      - attribute:update-values
                      - attribute:view
                      - attribute:view-any
                      - application-note:create
                      - application-note:view-any
                      - client:create
                      - client:update
                      - client:upload-signed-document
                      - client:view
                      - client:view-any
                      - comment:create
                      - comment:view-any
                      - comment:update
                      - comment:delete
                      - communication-log:create
                      - communication-template:view
                      - data-orchestration:run
                      - data-orchestration:view-any
                      - file:create
                      - file:update
                      - file:upload-contract
                      - file:upload-file-of-type
                      - file:upload-stip
                      - file:view
                      - funder:view
                      - funder:view-any
                      - metadata:view
                      - metadata:view-any
                      - metadata:create
                      - metadata:update
                      - metadata:delete
                      - note:create
                      - note:update
                      - note:view-any
                      - offer:confirm
                      - offer:create
                      - offer:delete
                      - offer:duplicate
                      - offer:update
                      - offer:update-status
                      - offer:view
                      - offer:view-any
                      - placement:create
                      - placement:update-status
                      - placement:view
                      - placement:view-any
                      - score-card-group:run
                      - score-card-group:run-any
                      - sms-conversation:view
                      - tracking-token:create
                      - tracking-token:delete
                      - tracking-token:update
                      - tracking-token:view-any
                      - user:impersonate
                      - workflow-snapshot:view
                      - workflow-template:apply-to-application
                      - workflow-template:view
                      - workflow-template:view-any
                rate_limits:
                  type: array
                  description: >-
                    Optional array of rate limits for this token. Each rate
                    limit must specify max_attempts (1-10,000), decay_minutes
                    (1-1440), and scope (, , , , , , , , ). Use '*' for a
                    wildcard that applies to all scopes. Example:
                    [{'max_attempts': 100, 'decay_minutes': 1, 'scope': 'api'}].
                  example: null
                  items:
                    type: object
                    nullable: true
                    properties:
                      max_attempts:
                        type: integer
                        description: >-
                          This field is required when <code>rate_limits</code>
                          is present. Must be at least 1. Must not be greater
                          than 10000.
                        example: 22
                      decay_minutes:
                        type: integer
                        description: >-
                          This field is required when <code>rate_limits</code>
                          is present. Must be at least 1. Must not be greater
                          than 1440.
                        example: 7
                      scope:
                        type: string
                        description: >-
                          This field is required when <code>rate_limits</code>
                          is present.
                        example: architecto
                        enum:
                          - api
                          - csrf
                          - stip_notification
                          - widget_resume
                          - signed_link
                          - verification_email
                          - '*'
                          - desktop_report_unauthenticated_ip
                          - desktop_report_unauthenticated_global
              required:
                - name
                - abilities
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                type: object
                example:
                  data:
                    id: null
                    name: Ms. Elisabeth Okuneva
                    description: Et fugiat sunt nihil accusantium.
                    abilities: ai-agent-session:view
                    last_used_at: null
                    revoked_at: null
                    expires_at: null
                    created_at: null
                    status: active
                properties:
                  data:
                    type: object
                    properties:
                      id:
                        type: string
                        example: null
                        nullable: true
                      name:
                        type: string
                        example: Ms. Elisabeth Okuneva
                      description:
                        type: string
                        example: Et fugiat sunt nihil accusantium.
                      abilities:
                        type: string
                        example: ai-agent-session:view
                      last_used_at:
                        type: string
                        example: null
                        nullable: true
                      revoked_at:
                        type: string
                        example: null
                        nullable: true
                      expires_at:
                        type: string
                        example: null
                        nullable: true
                      created_at:
                        type: string
                        example: null
                        nullable: true
                      status:
                        type: string
                        example: active
components:
  securitySchemes:
    default:
      type: http
      scheme: bearer
      description: >-
        <br>You can register for a new Lendflow API key on our <a
        style="color:blue;" href="https://app.lendflow.com/login">client
        portal</a> in less than 60 seconds. The Bearer Token needs to be
        included in all API requests made to the API Service in the following
        form: <div id="auth-example">Authorization: Bearer
        [YOUR_TOKEN]</div><div id="auth-reminder"><div
        id="edge-green"></div><div id="auth-reminder-text">You must replace
        [YOUR_TOKEN] with your personal API key.</div></div>

````