Skip to main content
A sandbox access token is a short-lived credential for working with sandboxes. Sandbox requests to /v1/sandboxes and a sandbox’s MCP server both require a token, not your Baseten API key. The Baseten CLI and SDKs create and refresh tokens for you. Request one yourself when your application calls the sandbox API or connects an MCP client directly. Your application calls POST /v1/token with its API key and uses the returned token for everything else. A token expires after 2 hours and can’t be renewed. A token carries your team memberships, so it isn’t scoped to one sandbox. Creating a token doesn’t create a sandbox or grant additional permissions. Keep both credentials out of agent prompts and out of code you submit to a sandbox. The token endpoint is experimental. Create tokens with a personal API key or a team API key with full access.

Request a token

Call Create a sandbox access token with the sandboxes scope:
A successful request returns HTTP 200 with the token and its expiration:
A successful request returns HTTP 200 with these fields. Don’t record the token in application logs.
string
Short-lived bearer token for sandbox requests and a sandbox’s MCP server.
string
Token expiration time in ISO 8601 format.
Send the token in the Authorization: Bearer <TOKEN> header of sandbox requests and of your MCP client’s configuration.

Replace expired tokens

You can’t renew a token. Request a new one before the current token’s expires_at time. A token can also stop working early if your team memberships or role change. If a previously valid token is rejected, request a new one. A token’s expiration is separate from the sandbox’s: an expired token doesn’t delete the sandbox, and a new token doesn’t extend the sandbox’s lifetime.

Next steps

Manage sandboxes

Create, inspect, and delete sandboxes with the Baseten CLI.

Manage sandbox images

Choose a built-in image, or create and version your own.