Create access token
Create an access token to use BitGo APIs. BitGo restricts access tokens in the production environment to specific IP addresses. However, access tokens in the test environment don't require an IP address restriction. If you omit a spending limit, you must unlock the token using the Unlock session endpoint on a regular basis to permit operations such as withdrawals. Therefore, BitGo recommends including a spending limit.
Body Params
object
-
scopearray of stringsThe permissions granted by this access token.
all- Access all actions in the test environment.crypto_compare- Call CryptoCompare API.enterprise_manage_all- Manage users and settings for any enterprise to which the user belongs.enterprise_view_all- View any enterprise to which the user belongs.metamask_institutional- [DEPRECATED] Enables using BitGo wallets in the MetaMask Institutional extension.openid- Verify your BitGo user ID using OpenID Connect.pending_approval_update- Approve or reject pending actions that require approval to proceed.portfolio_view- [DEPRECATED] Call the Portfolio API.profile- View your BitGo Profile.settlement_network_read- View your client's Go Network data, enabling allocations to and from your platform. Only for Go Network partners.settlement_network_write- Update your client's Go Network data, enabling allocations to and from your platform. Only for Go Network partners.trade_trade- Initiate trades.trade_view- View trades.trade_fix- Access the Trade FIX API gateway.wallet_approve- Approve policies and transactions for a wallet where the user is a wallet admin. Requires wallet context: use["wallet_approve:walletId"].wallet_approve_all- Approve transactions for any wallet where the user is a wallet admin within any enterprise to which the user belongs.wallet_approve_enterprise- Approve transactions for any wallet where the user is a wallet admin within a single enterprise.wallet_create- Create wallets.wallet_edit- Edit comments on a transfer. Requires wallet context: use["wallet_edit:walletId"].wallet_edit_all- Edit comments on all transfers within multiple enterprises.wallet_edit_enterprise- [DEPRECATED] Edit comments on all transfers within a single enterprise.wallet_freeze- Freeze a wallet. Requires wallet context: use["wallet_freeze:walletId"].wallet_freeze_all- Freeze any wallet within any enterprises to which the user belongs.wallet_manage- Manage settings for a wallet where the user is a wallet admin. Requires wallet context: use["wallet_manage:walletId"]wherewalletIdis the specific wallet ID. For managing multiple or all wallets, usewallet_manage_allorwallet_manage_enterprise.wallet_manage_all- Manage settings for any wallet where the user is a wallet admin within any enterprise to which the user belongs.wallet_manage_enterprise- Manage settings for any wallet where the user is a wallet admin within a single enterprise.wallet_spend- Initiate transactions from a wallet. Requires wallet context: use["wallet_spend:walletId"].wallet_spend_all- Initiate transactions from any wallet within any enterprise to which the user belongs.wallet_spend_enterprise- Initiate transactions from any wallet within a single enterprise.wallet_stake- Initiate staking transactions from a wallet. Requires wallet context: use["wallet_stake:walletId"].wallet_stake_all- Initiate staking transactions from any wallet within any enterprise to which the user belongs.wallet_view- View a wallet. Requires wallet context: use["wallet_view:walletId"].wallet_view_all- View any wallet within any enterprise to which the user belongs.wallet_view_enterprise- View any wallet within a single enterprise.
ONE OF
array of string enums
array of strings
-
durationnumberThe duration of the access token in seconds. -
labelstring requiredA label for the access token. -
otpstring requiredThe one-time password. -
adminbooleanTrue, if this access token has admin permissions. -
adminScopestring enumScope for admin permissions. Defaults to 'full' when omitted.readfull -
ipRestrictarray of strings nullableRestricts the access token to use only from the provided IP addresses. Required for access tokens in the production environment. Not required for access tokens in the test environment. -
enterprisestringThe enterprise ID that the user belongs to. -
spendingLimitsarray of objectsspendingLimits object
-
coinstring requiredA cryptocurrency symbol or token ticker symbol -
maxLimitboolean -
txValueLimitstring or number
-
-
allErc20TokensLimitobjectallErc20TokensLimit object
-
enabledboolean -
maxLimitboolean -
txValueLimitstring or number
-
-
accessTokenTemplateIdstringID of the AccessTokenTemplate to use as defaults for this token.
Template fields act as defaults — they are used when the corresponding field is absent from the request body. Any value you provide in the request, including an empty array, takes precedence.
For example, if the template has
scope: ['spend', 'transfer']and you sendscope: ['read'], the created token will havescope: ['read']. If you omitscopeentirely, the token getsscope: ['spend', 'transfer']from the template. -
permittedEnterprisesarray of strings -
permittedWalletsarray of strings
Responses
200
OK
Response Body
object
-
idstring required -
isExtensibleboolean required -
adminScopestring enumreadfull -
bitgoAdminPermissionsarray of strings -
clientstring -
createdstring date-time -
enterprisestring -
expiresstring date-time -
extensionAddressstring -
ipstring ipv4IP address of the client that requested this access token -
ipRestrictarray of strings -
labelstring -
originstringBitGo environment that issued this token -
tokenstring -
scopearray of strings -
unlockobjectunlock object
-
spendingLimitsmap of objectsspendingLimits object
-
<key>objectvalue object
-
txCountnumberThe transaction count limit for the coin -
txValuenumberThe transaction value limit for the coin -
txValueLimitnumberThe maximum transaction value limit for the coin
-
-
-
allErc20TokensLimitobjectallErc20TokensLimit object
-
enabledboolean requiredIndicates if the limit is enabled for all ERC20 tokens -
txCountnumber requiredThe transaction count limit for all ERC20 tokens -
txValuestring requiredThe transaction value limit for all ERC20 tokens -
txValueLimitInSmallUnitsstringThe transaction value limit in small units for all ERC20 tokens -
maxLimitbooleanIndicates if the maximum limit is enabled
-
-
expiresstring date-time -
timestring date-time -
txCountnumber -
txValuenumber -
txValueLimitnumber
-
-
userstring -
oauthobjectoauth object
-
oauthRequiredboolean -
expiresstring date-time
-
-
isMobileAccessTokenbooleanFlag indicating if this token was created via mobile session endpoint
400
Bad Request
Response Body
object
-
namestringError code -
contextmap of objects requiredProperties that apply to a specific error namecontext object
-
<key>object
-
-
errorstring requiredHuman-readable error message -
requestIdstring requiredClient request id