# Create Board Access Token

```
POST 
/v1/:slug/access_tokens
```

Exchange your API token for a short-lived, read-only token limited to one board and its sub-boards. Call this from your own server and hand the result to code that runs in a browser, so your API token never leaves your server. The returned token can list and search that board through `GET /boards`, `GET /boards/{token}`, `GET /boards/{token}/children`, `GET /boards/{token}/assets`, `GET /assets`, `GET /search` and `GET /ai_search`; every other endpoint, and every write, answers 403 `board_scoped_token`. It expires after at most one hour and cannot create further tokens. Revoking your API token does not revoke tokens already created from it; they expire on their own. Each call counts as one API request and each token has its own rate limit, so reuse a token for a visitor's whole session rather than creating one per page view.

## Request[​](#request "Direct link to request")

## Responses[​](#responses "Direct link to Responses")

* 200
* 401
* 403
* 404
* 422

successful

unauthenticated

the caller is not a Playbook API token

no such board in this workspace

expires\_in is not a whole number
