/v1/sandboxes and a sandbox’s MCP server
both require a token, not your Baseten API key.
The Baseten CLI and SDKs create and refresh tokens for you. Request one
yourself when your application calls the sandbox API or connects an MCP client
directly.
Your application calls
POST /v1/token
with its API key and uses the returned token for everything else. A token
expires after 2 hours and can’t be renewed.
A token carries your team memberships, so it isn’t
scoped to one sandbox. Creating a token doesn’t create a sandbox or grant
additional permissions. Keep both credentials out of agent prompts and out of
code you submit to a sandbox.
The token endpoint is experimental. Create tokens with a
personal API key or a team API key
with full access.
Request a token
Call Create a sandbox access token with thesandboxes scope:
- curl
- Python
200 with the token and its expiration:
200 with these fields. Don’t record the
token in application logs.
string
Short-lived bearer token for sandbox requests and a sandbox’s MCP server.
string
Token expiration time in ISO 8601 format.
Authorization: Bearer <TOKEN> header of sandbox
requests and of your MCP client’s configuration.
Replace expired tokens
You can’t renew a token. Request a new one before the current token’sexpires_at time. A token can also stop working early if your team
memberships or role change. If a previously valid token is rejected, request a
new one.
A token’s expiration is separate from the sandbox’s:
an expired token doesn’t delete the sandbox, and a new token doesn’t extend the
sandbox’s lifetime.
Next steps
Manage sandboxes
Create, inspect, and delete sandboxes with the Baseten CLI.
Manage sandbox images
Choose a built-in image, or create and version your own.