> ## Documentation Index
> Fetch the complete documentation index at: https://ona.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Host Authentication Token

> Creates a new authentication token for accessing remote hosts.

`Unary` · [`Runner Configurations`](/docs/api-reference/generated/runner-configuration/overview)

Creates a new authentication token for accessing remote hosts.

Use this method to:

* Set up SCM authentication
* Configure OAuth credentials
* Manage PAT tokens

### Examples

* Create OAuth token:

  Creates a new OAuth-based authentication token.

  ```yaml theme={null}
  runnerId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
  userId: "f53d2330-3795-4c5d-a1f3-453121af9c60"
  host: "github.com"
  token: "gho_xxxxxxxxxxxx"
  source: HOST_AUTHENTICATION_TOKEN_SOURCE_OAUTH
  expiresAt: "2024-12-31T23:59:59Z"
  refreshToken: "ghr_xxxxxxxxxxxx"
  ```

## Endpoint

```text theme={null}
POST /api/gitpod.v1.RunnerConfigurationService/CreateHostAuthenticationToken
```

Send a Bearer token as described in [Authentication](/docs/api-reference#authenticate-requests). If your organization uses a custom management-plane domain, replace `https://app.ona.com` with that domain.

## Request example

<CodeGroup>
  ```bash cURL theme={null}
  export ONA_HOST=https://app.ona.com
  export ONA_API_KEY=<your-token>

  curl --request POST \
    --url "$ONA_HOST/api/gitpod.v1.RunnerConfigurationService/CreateHostAuthenticationToken" \
    --header "Authorization: Bearer $ONA_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{
    "runnerId": "<runner-id>"
  }'
  ```

  ```python Python theme={null}
  import gitpod.v1.runner_configuration_pb2 as runner_configuration_pb2
  from ona_sdk import create_client_from_env

  ona = create_client_from_env()
  request = runner_configuration_pb2.CreateHostAuthenticationTokenRequest(
      runner_id="<runner-id>",
  )
  response = ona.services.runner_configuration.create_host_authentication_token(request)
  print(response)
  ```

  ```typescript TypeScript theme={null}
  import { create } from "@bufbuild/protobuf";
  import { createClientFromEnv } from "@gitpod/sdk";
  import { CreateHostAuthenticationTokenRequestSchema } from "@gitpod/sdk/gitpod/v1/runner_configuration_pb";

  async function main() {
    const ona = createClientFromEnv();
    const request = create(CreateHostAuthenticationTokenRequestSchema, {
      runnerId: "<runner-id>",
    });
    const response = await ona.services.runnerConfiguration.createHostAuthenticationToken(request);
    console.log(response);
  }

  main().catch(console.error);
  ```

  ```go Go theme={null}
  package main

  import (
  	"context"
  	"fmt"
  	"log"

  	"connectrpc.com/connect"
  	"github.com/gitpod-io/gitpod-sdk-go/sdk"
  	gitpodpb "github.com/gitpod-io/gitpod-sdk-go/v1"
  )

  func main() {
  	ona, err := sdk.NewFromEnv()
  	if err != nil {
  		log.Fatal(err)
  	}

  	request := connect.NewRequest(&gitpodpb.CreateHostAuthenticationTokenRequest{
  		RunnerId: "<runner-id>",
  	})
  	response, err := ona.Services.RunnerConfiguration.CreateHostAuthenticationToken(context.Background(), request)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(response.Msg)
  }
  ```

  ```json Request body theme={null}
  {
    "runnerId": "<runner-id>"
  }
  ```
</CodeGroup>

## Request

`gitpod.v1.CreateHostAuthenticationTokenRequest`

| Field           | Type                                                                              | Required | Description                                                                                                          |
| --------------- | --------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------- |
| `runnerId`      | string                                                                            | No       | Constraints: `string.uuid=true`.                                                                                     |
| `userId`        | string                                                                            | No       | **Deprecated.** Deprecated: Use principal\_id and principal\_type instead Constraints: `ignore=1, string.uuid=true`. |
| `host`          | string                                                                            | No       | Constraints: `string.min_len=1`.                                                                                     |
| `token`         | string                                                                            | No       | Constraints: `string.min_len=1`.                                                                                     |
| `source`        | [HostAuthenticationTokenSource](#enum-gitpod-v1-host-authentication-token-source) | No       | Constraints: `enum.defined_only=true`.                                                                               |
| `expiresAt`     | RFC 3339 timestamp                                                                | No       |                                                                                                                      |
| `refreshToken`  | string                                                                            | No       |                                                                                                                      |
| `integrationId` | string                                                                            | No       | Constraints: `ignore=1, string.uuid=true`.                                                                           |
| `scopes`        | array of string                                                                   | No       | Maximum 100 scopes allowed (101 for validation purposes) Constraints: `repeated.max_items=101`.                      |
| `subject`       | [Subject](#type-gitpod-v1-subject)                                                | No       | Subject identifies the principal (user or service account) for the token Constraints: `ignore=1`.                    |

## Response

`gitpod.v1.CreateHostAuthenticationTokenResponse`

| Field   | Type                                                                 | Required | Description                   |
| ------- | -------------------------------------------------------------------- | -------- | ----------------------------- |
| `token` | [HostAuthenticationToken](#type-gitpod-v1-host-authentication-token) | Yes      | Constraints: `required=true`. |

## Related types

<a id="type-gitpod-v1-host-authentication-token" />

<Accordion title="HostAuthenticationToken">
  `gitpod.v1.HostAuthenticationToken`

  | Field           | Type                                                                              | Required | Description                                                               |
  | --------------- | --------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------- |
  | `id`            | string                                                                            | No       |                                                                           |
  | `runnerId`      | string                                                                            | No       |                                                                           |
  | `userId`        | string                                                                            | No       | **Deprecated.** Deprecated: Use principal\_id and principal\_type instead |
  | `host`          | string                                                                            | No       |                                                                           |
  | `source`        | [HostAuthenticationTokenSource](#enum-gitpod-v1-host-authentication-token-source) | No       |                                                                           |
  | `expiresAt`     | RFC 3339 timestamp                                                                | No       |                                                                           |
  | `integrationId` | string                                                                            | No       |                                                                           |
  | `scopes`        | array of string                                                                   | No       |                                                                           |
  | `subject`       | [Subject](#type-gitpod-v1-subject)                                                | No       | Subject identifies the principal (user or service account) for the token  |
</Accordion>

<a id="type-gitpod-v1-subject" />

<Accordion title="Subject">
  `gitpod.v1.Subject`

  | Field       | Type                                   | Required | Description                                                                      |
  | ----------- | -------------------------------------- | -------- | -------------------------------------------------------------------------------- |
  | `id`        | string                                 | No       | id is the UUID of the subject Constraints: `ignore=1, string.uuid=true`.         |
  | `principal` | [Principal](#enum-gitpod-v1-principal) | No       | Principal is the principal of the subject Constraints: `enum.defined_only=true`. |
</Accordion>

<a id="enum-gitpod-v1-host-authentication-token-source" />

<Accordion title="HostAuthenticationTokenSource">
  | Value                                          | Number | Description |
  | ---------------------------------------------- | -----: | ----------- |
  | `HOST_AUTHENTICATION_TOKEN_SOURCE_UNSPECIFIED` |      0 |             |
  | `HOST_AUTHENTICATION_TOKEN_SOURCE_OAUTH`       |      1 |             |
  | `HOST_AUTHENTICATION_TOKEN_SOURCE_PAT`         |      2 |             |
</Accordion>

<a id="enum-gitpod-v1-principal" />

<Accordion title="Principal">
  | Value                       | Number | Description |
  | --------------------------- | -----: | ----------- |
  | `PRINCIPAL_UNSPECIFIED`     |      0 |             |
  | `PRINCIPAL_ACCOUNT`         |      1 |             |
  | `PRINCIPAL_USER`            |      2 |             |
  | `PRINCIPAL_RUNNER`          |      3 |             |
  | `PRINCIPAL_ENVIRONMENT`     |      4 |             |
  | `PRINCIPAL_SERVICE_ACCOUNT` |      5 |             |
  | `PRINCIPAL_RUNNER_MANAGER`  |      6 |             |
</Accordion>
