> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an embed sign-in token

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Creates a single-use sign-in token for a provisioned app user and returns `embed_url`, the chosen surface's address with the token on it. Load it in an iframe and the app opens signed in as that user. `live_preview` loads only while the app's sandbox is running. A workspace API key needs the **Mint embed sign-in tokens** permission. Limited to 300 requests a minute per app. Higher plans get a higher limit.



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/embed-tokens
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/embed-tokens:
    post:
      summary: Create an embed sign-in token
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Creates a single-use sign-in token for a provisioned app user and
        returns `embed_url`, the chosen surface's address with the token on it.
        Load it in an iframe and the app opens signed in as that user.
        `live_preview` loads only while the app's sandbox is running. A
        workspace API key needs the **Mint embed sign-in tokens** permission.
        Limited to 300 requests a minute per app. Higher plans get a higher
        limit.
      operationId: create_embed_token_api_apps__app_id__embed_tokens_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EmbedTokenPayload'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmbedTokenResponse'
        '400':
          description: >-
            The app has no address for `target`: error.code app_not_deployed or
            app_has_no_slug.
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            The email belongs to the app's owner, an editor or a service
            account: error.code privileged_user.
        '404':
          description: 'The email isn''t provisioned for this app: error.code unknown_user.'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: The app went over its per-minute limit for embed sign-in tokens.
      security:
        - PersonalAccessTokenAuth: []
        - WorkspaceApiKeyAuth: []
components:
  schemas:
    EmbedTokenPayload:
      properties:
        email:
          type: string
          format: email
          title: Email
          description: The app user's email
        target:
          $ref: '#/components/schemas/EmbedTarget'
          description: >-
            Which of the app's surfaces to frame: live_site (the default, the
            published app), latest_preview (main's static build) or live_preview
            (the running sandbox).
          default: live_site
      additionalProperties: false
      type: object
      required:
        - email
      title: EmbedTokenPayload
      description: The app user to mint for, and which of the app's surfaces to frame.
    EmbedTokenResponse:
      properties:
        token:
          type: string
          title: Token
          description: >-
            The single-use sign-in token. Already on `embed_url`; you don't need
            to send it anywhere yourself.
          example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.sig
        expires_in:
          type: integer
          title: Expires In
          description: Seconds until the token expires.
          example: 60
        embed_url:
          type: string
          title: Embed Url
          description: >-
            The chosen surface's address with the token on it. Load it in an
            iframe.
          example: >-
            https://weekly-report.base44.app/?ott=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.e30.sig
      type: object
      required:
        - token
        - expires_in
        - embed_url
      title: EmbedTokenResponse
      description: A single-use sign-in token, and the URL that spends it.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    EmbedTarget:
      type: string
      enum:
        - live_site
        - latest_preview
        - live_preview
      title: EmbedTarget
      description: >-
        The surfaces a platform may frame, named by their ``UrlType``.


        A subset rather than ``UrlType`` itself: the rest of that enum is either

        internal (``platform``, ``pentest``) or addresses a revision, and a
        public

        payload should not offer what it will only refuse.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'
    WorkspaceApiKeyAuth:
      type: apiKey
      in: header
      name: api_key
      description: 'Workspace API key, sent as `api_key: <key>`.'

````