Partner API
Mint tenant API tokens
Issue a replacement tenant token for a managed account.
POST
/
api
/
partner
/
v1
/
accounts
/
{id}
/
tokens
Mint a tenant API token
curl --request POST \
--url https://spitshake.io/api/partner/v1/accounts/{id}/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://spitshake.io/api/partner/v1/accounts/{id}/tokens"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://spitshake.io/api/partner/v1/accounts/{id}/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://spitshake.io/api/partner/v1/accounts/{id}/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://spitshake.io/api/partner/v1/accounts/{id}/tokens"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://spitshake.io/api/partner/v1/accounts/{id}/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://spitshake.io/api/partner/v1/accounts/{id}/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"account": {
"id": 412,
"external_id": "firm-8675309"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "2ff154a0405e..."
}This endpoint mints a tenant API token for the account’s provisioned partner admin. If that user
is missing or archived, the oldest active admin is used. The insert and audit event are atomic.
The raw token is shown only in the first response and exact idempotent replays. Store it securely.
The token authenticates the ordinary tenant API, not the Partner API.
curl -X POST https://spitshake.io/api/partner/v1/accounts/412/tokens \
-H "Authorization: Bearer $SPITSHAKE_PARTNER_KEY" \
-H "Idempotency-Key: token-rotation-2026-07-22" \
-H "Content-Type: application/json" \
-d '{}'
201
{
"account": {
"id": 412,
"external_id": "firm-8675309"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "2ff154a0405e..."
}
| Status | Meaning |
|---|---|
401 | Missing or invalid partner key. |
403 | Partner access is suspended. |
404 | Account is not owned by this partner. |
409 | Another request with this endpoint/key is still in flight. |
422 | No active admin exists, or the idempotency key was reused with a different body. |
Authorizations
Operator-issued partner key. Accepted only under /api/partner/v1.
Headers
Maximum string length:
255Path Parameters
Body
application/json
The body is of type object.
⌘I
Mint a tenant API token
curl --request POST \
--url https://spitshake.io/api/partner/v1/accounts/{id}/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://spitshake.io/api/partner/v1/accounts/{id}/tokens"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://spitshake.io/api/partner/v1/accounts/{id}/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://spitshake.io/api/partner/v1/accounts/{id}/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://spitshake.io/api/partner/v1/accounts/{id}/tokens"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://spitshake.io/api/partner/v1/accounts/{id}/tokens")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://spitshake.io/api/partner/v1/accounts/{id}/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"account": {
"id": 412,
"external_id": "firm-8675309"
},
"admin": {
"id": 991,
"email": "admin@acme.example"
},
"api_token": "2ff154a0405e..."
}
