> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Port Access Token

> Creates an access token for a specific port on an environment.

`Unary` · [`Environments`](/docs/api-reference/generated/environment/overview)

Creates an access token for a specific port on an environment.

The token grants access to the specified port based on the port's admission level.
Tokens are short-lived (\~1 hour) with refresh tokens for long-running connections.

### Examples

* Generate port access token:

  Creates a token for accessing port 8080 on an environment.

  ```yaml theme={null}
  environmentId: "07e03a28-65a5-4d98-b532-8ea67b188048"
  port: 8080
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.EnvironmentService/CreatePortAccessToken
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.EnvironmentService/CreatePortAccessToken" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "environmentId": "<environment-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.environment_pb2 as environment_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = environment_pb2.CreatePortAccessTokenRequest(
      environment_id="<environment-id>",
  )
  response = ona.services.environment.create_port_access_token(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreatePortAccessTokenRequestSchema } from "@gitpod/sdk/gitpod/v1/environment_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreatePortAccessTokenRequestSchema, {
      environmentId: "<environment-id>",
    });
    const response = await ona.services.environment.createPortAccessToken(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreatePortAccessTokenRequest{
  		EnvironmentId: "<environment-id>",
  	})
  	response, err := ona.Services.Environment.CreatePortAccessToken(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "environmentId": "<environment-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreatePortAccessTokenRequest`

| Field           | Type    | Required | Description                                                                                                                   |
| --------------- | ------- | -------- | ----------------------------------------------------------------------------------------------------------------------------- |
| `environmentId` | string  | No       | environment\_id specifies the environment for which the port access token should be created. Constraints: `string.uuid=true`. |
| `port`          | integer | No       | port specifies the port number for which the access token should be created. Constraints: `int32.gte=1, int32.lte=65535`.     |

## Response

`gitpod.v1.CreatePortAccessTokenResponse`

| Field         | Type   | Required | Description                                                                                   |
| ------------- | ------ | -------- | --------------------------------------------------------------------------------------------- |
| `accessToken` | string | Yes      | access\_token is the token that can be used to access the port. Constraints: `required=true`. |
