> ## Documentation Index
> Fetch the complete documentation index at: https://benchgen.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a token

> The normal way to create a token is the web app: Profile Settings > Platform API tokens (you are signed in with your session there, nothing else is needed). Programmatic creation works only with an interactive credential: the `sessionid` cookie of a signed-in browser session, or an interactive token from `POST /api/api-token-auth/`. a platform token cannot mint tokens and gets 403, so a leaked token can never widen its own reach. The response carries `token` with the raw secret EXACTLY ONCE; only its hash is stored.



## OpenAPI

````yaml POST /api/tokens/
openapi: 3.0.3
info:
  title: BenchGen Platform API
  version: 1.0.0
  description: >-
    One API for the whole BenchGen platform: model catalogue and serving,
    fine-tuning and benchmarks, datasets (knowledge), and billing.


    ## Authentication

    Every request uses the same credential: a platform API token sent as
    `Authorization: Bearer bgn_...`.

    Create tokens in the web app under Profile Settings > Platform API tokens
    (the secret is shown exactly once), or via `POST /api/tokens/` with an
    interactive session. Revoking a token disables it platform-wide within 60
    seconds.


    ## Scopes

    A token carries scopes chosen at creation; a request outside the token's
    scopes gets `403` with an explanatory message.


    | scope | grants |

    |---|---|

    | `models:read` | read model catalogues, job status, logs, GPU info |

    | `models:write` | deploy, train, merge, stop models and jobs |

    | `benchmark:read` | read benchmark runs and results |

    | `benchmark:run` | launch benchmark runs |

    | `benchmark:create` | create benchmarks in your account (drafts, Excel,
    bundles, specs); counts toward the creation limit |

    | `benchmark:manage` | edit and delete benchmarks you own or collaborate on
    |

    | `benchmark:publish` | publish and unpublish benchmarks you own or
    collaborate on |

    | `knowledge:read` | read your datasets and fine-tuning data |

    | `knowledge:write` | create, edit and delete datasets and fine-tuning data
    |

    | `billing:read` | read your balance and usage |

    | `agents:chat` | chat with your own agents through the API |

    | `agents:manage` | manage your agents, knowledge bases and channels |

    | `admin` | everything the account can do (staff accounts only) |


    ## For agents

    This document plus `/api/llms.txt` are the machine-readable entry points.
    Responses are JSON. Errors use conventional status codes; the body carries
    `error` or `message`. Knowledge endpoints return `[{"data": [...], "meta":
    {...}}]`.


    The complete auto-generated schema of every endpoint (including internal
    ones) lives at `/api/public-docs.json` (Swagger 2.0); this document is the
    curated, stable, supported surface.
  contact:
    url: https://benchgen.com
servers:
  - url: https://api.benchgen.com
security:
  - platformToken: []
tags:
  - name: auth
    description: Token introspection for services and integrations
  - name: tokens
    description: Manage your platform API tokens
  - name: models
    description: Model catalogue and serving
  - name: finetune
    description: Fine-tuning jobs, inference deployments, GPUs
  - name: knowledge
    description: Datasets and fine-tuning data (knowledge API)
  - name: billing
    description: Balance and usage
  - name: agents
    description: Chat with your agents (OpenAI-compatible facade)
  - name: benchmark
    description: Public benchmark (competition) listings.
paths:
  /api/tokens/:
    post:
      tags:
        - tokens
      summary: Create a token (interactive sign-in only)
      description: >-
        The normal way to create a token is the web app: Profile Settings >
        Platform API tokens (you are signed in with your session there, nothing
        else is needed). Programmatic creation works only with an interactive
        credential: the `sessionid` cookie of a signed-in browser session, or an
        interactive token from `POST /api/api-token-auth/`. a platform token
        cannot mint tokens and gets 403, so a leaked token can never widen its
        own reach. The response carries `token` with the raw secret EXACTLY
        ONCE; only its hash is stored.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - scopes
              properties:
                scopes:
                  type: array
                  items:
                    type: string
                    enum:
                      - models:read
                      - models:write
                      - benchmark:read
                      - benchmark:run
                      - benchmark:create
                      - benchmark:manage
                      - benchmark:publish
                      - knowledge:read
                      - knowledge:write
                      - billing:read
                      - agents:chat
                      - agents:manage
                      - admin
                  example:
                    - models:read
                    - knowledge:read
                  description: >-
                    Scopes the token will carry, fixed at creation. `admin` is
                    accepted only for staff accounts; `internal:*` scopes can
                    never be minted through the API.
                name:
                  type: string
                  example: CI pipeline
                expires_in_days:
                  type: integer
                  description: Omit or 0 for no expiry, max 3650
      responses:
        '201':
          description: Created; `token` holds the secret, shown once
        '400':
          description: Unknown scope, internal scope, admin without staff, or bad expiry
        '403':
          description: Authenticated with a platform token (tokens cannot mint tokens)
      security:
        - session: []
        - interactiveToken: []
components:
  securitySchemes:
    platformToken:
      type: http
      scheme: bearer
      bearerFormat: bgn_ opaque token
      description: >-
        Platform API token created under Profile Settings > Platform API tokens.
        Scopes are fixed at creation.
    session:
      type: apiKey
      in: cookie
      name: sessionid
      description: >-
        Interactive browser session, the `sessionid` cookie Django sets when you
        sign in to the web app (benchgen.com). To script this endpoint, sign in
        in a browser and copy the `sessionid` cookie from DevTools > Application
        > Cookies. The recommended path is simply the web app itself: Profile
        Settings > Platform API tokens. Platform tokens are deliberately refused
        here (403), so a leaked token can never mint successors.
    interactiveToken:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Interactive token from `POST /api/api-token-auth/`, sent as
        `Authorization: Token <token>`. Unlike a platform `bgn_` token this is a
        full interactive credential (it is minted from your password), so it may
        create and revoke platform tokens. Keep it out of CI; put a scoped
        `bgn_` token there instead.

````