Skip to main content
POST
Create a token

Authorizations

Authorization
string
header
required

You can use an OAuth2 JWT bearer token in the Authorization header of your API requests for supported endpoints: Authorization: Bearer <YOUR_JWT_HERE>. These tokens are valid for 10 minutes and can be requested via the access token endpoint endpoint.

Headers

x-idempotency-key
string<uuid>
required

Idempotency key to be used. Sending again the same key would return the same result without re-executing the update.

Path Parameters

instrumentId
string<uuid>
required

Identifier of the resource in Payrails.

Body

application/json
providerId
string<uuid>
required

Id of the provider the token belongs to.

type
enum<string>
required

Type of the token.

Available options:
network,
vault,
psp,
networkOffers,
networkGateway
reference
string
required

Unique identifier of the token in the provider's system.

providerConfigId
string<uuid>

Id of the configuration in the provider the token belongs to.

meta
object

Any merchant or provider-specific data that should be stored for context in the token, e.g. holderReference is required for Adyen tokens.

Response

Created.

id
string<uuid>
required

Id of the token in Payrails.

createdAt
string<date-time>
required

Date and time when the Token was created in Payrails.

updatedAt
string<date-time>
required

When the Token was last updated.

instrumentId
string<uuid>
required

Id of the payment instrument the token belongs to.

status
enum<string>
required

Status of the token.

Available options:
created,
enabled,
disabled,
deleted
type
enum<string>
required

Type of the token.

Available options:
network,
vault,
psp,
networkOffers,
networkGateway
providerId
string<uuid>
required

Id of the provider the token belongs to.

reference
string
required

Unique identifier of the token in the provider's system.

providerConfigId
string<uuid>

Id of the configuration in the provider the token belongs to.

meta
object

Any merchant or provider-specific data that should be stored for context in the token.

Last modified on October 1, 2026