Mint a user token for a subject you authenticated
POST/auth/delegated-token
Machine token. Called by your backend, using your client_credentials token.
Your backend has already established who the person is; this turns that into a wallet user token you can hand to your app.
Call it with your machine token, naming the person by the externalUserRef you registered them under. What comes back is an ordinary user token, scoped to that person — every /me/*
operation will resolve to them and nothing else.
The token records how it was obtained: amr: ["tenant_delegated"], plus an act claim naming your client. Months later, a disputed transaction can still be told apart from one where
we verified the person ourselves.
No refresh token is issued. A refresh would let the session outlive your ability to re-assert the person, which is authority you have not given us. Mint a new one instead — it is a single call and your backend already holds the credential.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 500
OK
Malformed request — validation failure, or a header such as Idempotency-Key is missing or not a UUID.
Missing, expired, or untrusted bearer token.
Authenticated but not permitted — the caller's role or scope does not grant this operation, or the resource belongs to another tenant.
The referenced wallet, transaction, user, or tenant does not exist within the caller's tenant.
Idempotency conflict — a request with this Idempotency-Key is still in flight. Retry once it settles. A key belonging to an already-completed request is NOT an error: the original response is replayed with its original status.
The request is well-formed but violates a business rule — for example a posting that would breach a wallet fund's balance floor, a transaction type not enabled for the tenant, a per-transaction or daily issuance cap, or an operation on a frozen wallet.
Unexpected server error.