> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange an API key for a token

> Trade an api key for a session token of at most fifteen minutes, and send that token as `Authorization: Bearer` on every other call. Call this one with no token.

A refusal is still an answer with a row: `token` is null and `error_code` and `message` say why — an unknown, expired or revoked key among them.

`p_on_behalf_of` takes a person's email address and mints a token naming them instead of the key's own account, so a write records the person who asked for it. What that session may do is what the person, the key's account and the key's scopes all allow.



## OpenAPI

````yaml /api-reference/integration.json post /rpc/exchange_api_key
openapi: 3.0.0
info:
  description: >-
    The calls an integration needs first. Every endpoint the application uses is
    in the complete reference.
  title: Asset Infinity integration API
  version: 12.2.3
servers:
  - url: https://app.assetinfinity.ai/api
security: []
tags:
  - description: >-
      Exchange an API key, or an email and password, for a short-lived session
      token, and send it as `Authorization: Bearer <token>` on every other call.
    name: Signing in
  - description: >-
      Where assets are and work happens. A location belongs to a site and may
      sit inside another location.
    name: Sites and locations
  - description: >-
      The asset register: read it, add to it, correct it, move an asset between
      sites and locations, and change its status.
    name: Assets
  - description: >-
      Report a problem. A request is triaged by a person, who turns it into a
      work order or turns it down.
    name: Work requests
  - description: >-
      Raise a job, give it to somebody, move it through the organisation's
      statuses, complete it and close it.
    name: Work orders
  - description: >-
      Send readings in. A meter reading brings the meter forward and raises any
      maintenance the usage has made due. A sensor reading can open or clear an
      alert.
    name: Meters and sensors
  - description: >-
      The part catalogue and what is on the shelf in each store, and the three
      movements an outside system most often records: a delivery in, an issue
      out and a correction.
    name: Parts and stock
  - description: >-
      Have the product call your system when something happens, instead of
      asking it on a timer.
    name: Webhooks
  - description: >-
      The calls behind every register that has no call of its own, answers to
      the organisation's own fields, and the two calls that answer what to send.
      `list_options` returns the ids a field accepts. `describe_call` returns
      the fields any call takes.
    name: Any record
externalDocs:
  description: PostgREST Documentation
  url: https://postgrest.org/en/v12/references/api.html
paths:
  /rpc/exchange_api_key:
    post:
      tags:
        - Signing in
      summary: Exchange an API key for a token
      description: >-
        Trade an api key for a session token of at most fifteen minutes, and
        send that token as `Authorization: Bearer` on every other call. Call
        this one with no token.


        A refusal is still an answer with a row: `token` is null and
        `error_code` and `message` say why — an unknown, expired or revoked key
        among them.


        `p_on_behalf_of` takes a person's email address and mints a token naming
        them instead of the key's own account, so a write records the person who
        asked for it. What that session may do is what the person, the key's
        account and the key's scopes all allow.
      parameters:
        - $ref: '#/components/parameters/preferParams'
      requestBody:
        content:
          application/json:
            schema:
              description: >-
                Trade an api key for a session token of at most fifteen minutes,
                and send that token as `Authorization: Bearer` on every other
                call. Call this one with no token.


                A refusal is still an answer with a row: `token` is null and
                `error_code` and `message` say why — an unknown, expired or
                revoked key among them.


                `p_on_behalf_of` takes a person's email address and mints a
                token naming them instead of the key's own account, so a write
                records the person who asked for it. What that session may do is
                what the person, the key's account and the key's scopes all
                allow.
              properties:
                p_key:
                  format: text
                  type: string
                p_on_behalf_of:
                  format: text
                  type: string
              required:
                - p_key
              type: object
          application/vnd.pgrst.object+json:
            schema:
              description: >-
                Trade an api key for a session token of at most fifteen minutes,
                and send that token as `Authorization: Bearer` on every other
                call. Call this one with no token.


                A refusal is still an answer with a row: `token` is null and
                `error_code` and `message` say why — an unknown, expired or
                revoked key among them.


                `p_on_behalf_of` takes a person's email address and mints a
                token naming them instead of the key's own account, so a write
                records the person who asked for it. What that session may do is
                what the person, the key's account and the key's scopes all
                allow.
              properties:
                p_key:
                  format: text
                  type: string
                p_on_behalf_of:
                  format: text
                  type: string
              required:
                - p_key
              type: object
          application/vnd.pgrst.object+json;nulls=stripped:
            schema:
              description: >-
                Trade an api key for a session token of at most fifteen minutes,
                and send that token as `Authorization: Bearer` on every other
                call. Call this one with no token.


                A refusal is still an answer with a row: `token` is null and
                `error_code` and `message` say why — an unknown, expired or
                revoked key among them.


                `p_on_behalf_of` takes a person's email address and mints a
                token naming them instead of the key's own account, so a write
                records the person who asked for it. What that session may do is
                what the person, the key's account and the key's scopes all
                allow.
              properties:
                p_key:
                  format: text
                  type: string
                p_on_behalf_of:
                  format: text
                  type: string
              required:
                - p_key
              type: object
          text/csv:
            schema:
              description: >-
                Trade an api key for a session token of at most fifteen minutes,
                and send that token as `Authorization: Bearer` on every other
                call. Call this one with no token.


                A refusal is still an answer with a row: `token` is null and
                `error_code` and `message` say why — an unknown, expired or
                revoked key among them.


                `p_on_behalf_of` takes a person's email address and mints a
                token naming them instead of the key's own account, so a write
                records the person who asked for it. What that session may do is
                what the person, the key's account and the key's scopes all
                allow.
              properties:
                p_key:
                  format: text
                  type: string
                p_on_behalf_of:
                  format: text
                  type: string
              required:
                - p_key
              type: object
        required: true
      responses:
        '200':
          description: OK
components:
  parameters:
    preferParams:
      description: Preference
      in: header
      name: Prefer
      required: false
      schema:
        enum:
          - params=single-object
        type: string

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.