> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nasiko.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue a short-lived agent identity token for a local SDK process. The caller

> Issue a short-lived agent identity token for a local SDK process. The caller
must own the agent; the signing secret never leaves the control plane.



## OpenAPI

````yaml /api-reference/openapi.json post /api/agents/{id}/llm-token
openapi: 3.1.0
info:
  title: Nasiko API
  description: >-
    HTTP API for the Nasiko OpenRuntime: agents, coding harnesses, TokenOps,
    routing, MCP, and secrets. Spec is generated from annotated routes; some
    surfaces are documented on the hand-written pages alongside this file.
  license:
    name: ''
  version: 0.1.0
servers: []
security: []
tags:
  - name: secrets
    description: Encrypted per-user agent secrets
  - name: catalog
    description: >-
      Agent catalog: registration, discovery, versions, per-agent secrets, and
      source import
  - name: agents
    description: >-
      Agent lifecycle: deployments, LLM routing config, update/rollback,
      upload-and-deploy
  - name: orchestrator
    description: >-
      A2A dispatch: routing-engine/ReAct orchestrator and direct agent chat,
      plus routing stats
  - name: users
    description: >-
      User management: CRUD, roles, credentials, accessible agents
      (superuser-only)
  - name: usage
    description: Per-user token usage and cost reporting
  - name: observability
    description: Sessions, traces, spans, agent logs, and FinOps reporting
  - name: llm-router
    description: LLM routing presets, provider/model catalog, and tier→model registry
  - name: mcp
    description: >-
      MCP gateway: agent-facing JSON-RPC tool calls, connector
      registration/upload/sharing, credentials & OAuth, and per-agent tool
      permissions
paths:
  /api/agents/{id}/llm-token:
    post:
      tags:
        - agents
      summary: >-
        Issue a short-lived agent identity token for a local SDK process. The
        caller
      description: >-
        Issue a short-lived agent identity token for a local SDK process. The
        caller

        must own the agent; the signing secret never leaves the control plane.
      operationId: issue_llm_token
      parameters:
        - name: id
          in: path
          description: Agent id
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: Short-lived LLM routing token
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LlmTokenEnvelope'
        '403':
          description: Caller is not the agent owner
        '404':
          description: No such agent
        '503':
          description: LLM router authentication is not configured
components:
  schemas:
    LlmTokenEnvelope:
      type: object
      required:
        - data
        - status_code
        - message
      properties:
        data:
          $ref: '#/components/schemas/LlmTokenResponse'
        message:
          type: string
        status_code:
          type: integer
          format: int32
          minimum: 0
    LlmTokenResponse:
      type: object
      required:
        - token
        - expires_at
      properties:
        expires_at:
          type: string
          format: date-time
        token:
          type: string

````