> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arcenpay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an access token (identify)

> Upserts a company and user, then returns a short-lived signed JWT for ArcenEmbed and customer-scoped endpoints. Backs the SDK `identify()` method.



## OpenAPI

````yaml /openapi.yaml post /access-tokens
openapi: 3.0.3
info:
  title: ArcenPay API
  description: >
    The ArcenPay REST API powers subscription billing, entitlements, usage
    metering,

    payment links, checkout sessions, and autonomous agent payments across EVM
    (BOT Chain,

    Base, Arc, Sepolia) and Stellar.


    Every endpoint that accepts an API key supports the `Authorization: Bearer
    <key>` header.

    Key prefixes: `sk_…` (secret), `rk_…` (restricted), `pk_…` (publishable,
    read-only),

    `api_…` (legacy). Company-scoped customer endpoints accept an embed access
    token

    (`arc_tok_…` or a signed JWT from `identify()`). See the Authentication page
    for the

    full endpoint auth matrix.


    Manage catalog, environments, invoices, webhooks, feature flags, and agent
    configuration

    from the *dashboard* — those are not part of the developer-facing API
    reference.
  version: 1.0.0
servers:
  - url: https://api.arcenpay.com/api/v1
    description: Production
  - url: http://localhost:3300/api/v1
    description: Local development
security:
  - bearerAuth: []
tags:
  - name: Credentials
    description: >-
      API keys, secret/publishable/restricted credentials, and short-lived
      tokens.
  - name: Companies
    description: Customer organizations, identity synchronization, and feature overrides.
  - name: Users
    description: Customer end-users associated with company organizations.
  - name: Events
    description: Ingest customer usage events and identification signals.
  - name: Access control
    description: >-
      Real-time entitlement checks, feature flags, and metered credit
      consumption.
  - name: Subscriptions
    description: >-
      On-chain subscription activation, self-serve plan switching, proration,
      and cancellation.
  - name: Checkout sessions
    description: Hosted checkout session lifecycle and status lookup.
  - name: Payment links
    description: Crypto payment links and dynamic payment URLs.
  - name: Autonomous agents
    description: >-
      Agent permissions, budget checking, on-chain funding, and auto-topup
      dispatch.
  - name: Mandates
    description: Recurring billing authorizations and mandate lifecycle.
  - name: Coupons
    description: Discount code validation and proration quoting.
  - name: zkTLS proofs
    description: Zero-knowledge TLS proofs verification via Reclaim Protocol.
  - name: Public
    description: Unauthenticated payment link specifications and checkout sessions.
  - name: Escrow
    description: >-
      Autonomous commit-reveal escrow reservations, release settlement, and
      dispute handling.
  - name: Features
    description: Feature catalog definitions, feature types, and linked plan entitlements.
paths:
  /access-tokens:
    post:
      tags:
        - Credentials
      summary: Create an access token (identify)
      description: >-
        Upserts a company and user, then returns a short-lived signed JWT for
        ArcenEmbed and customer-scoped endpoints. Backs the SDK `identify()`
        method.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                company:
                  type: object
                  description: >-
                    At least one of id, wallet, or email required. Auto-created
                    if missing.
                  properties:
                    id:
                      type: string
                    wallet:
                      type: string
                    email:
                      type: string
                    name:
                      type: string
                    traits:
                      type: object
                      additionalProperties: true
                user:
                  type: object
                  properties:
                    id:
                      type: string
                    clerk_user_id:
                      type: string
                    wallet:
                      type: string
                    name:
                      type: string
                    email:
                      type: string
                expires_in:
                  type: integer
                  description: Token lifetime in seconds (60-86400). Default 3600.
      responses:
        '200':
          description: Access token created
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      token:
                        type: string
                      expires_at:
                        type: string
                        format: date-time
                      company_id:
                        type: string
                      user_id:
                        type: string
                        nullable: true
        '409':
          $ref: '#/components/responses/Conflict'
      security:
        - bearerAuth: []
components:
  responses:
    Conflict:
      description: >-
        The request conflicts with current state (duplicate wallet, existing
        key, replay, etc.).
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
              code:
                type: string
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: sk_… / rk_… / pk_… / api_…

````