# mv.clientTokens

> The clientTokens methods of @morevoice/sdk: Short-lived tokens that let a browser start one call.

Short-lived tokens that let a browser start one call. These methods are on `mv.clientTokens`, where `mv` is your client (see [the Node.js SDK](https://docs.morevoice.ai/sdk/node/#connect)). Each one returns the response object and throws when the API answers with an error.

## `create()`

**Create a client token.** Mint, on your server, a short-lived token a browser uses to start one call to one assistant with @morevoice/web (`MoreVoiceWeb.start({ token })`). The token works once, until `expires_at`; bind it to your site with `origin`. It carries the call's ID, so you can follow the call (webhooks, GET /v1/calls/{id}/events) before it starts.

```ts
mv.clientTokens.create(body?: ClientTokensCreateData["body"], options?: RequestOptions): Promise<ClientTokensCreateResponse>
```

`POST /client_tokens` · [API reference](https://docs.morevoice.ai/api/operations/client_tokens_create/)

### Parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `body.agent_user_id` | `string` | no | The agent whose softphone the token opens (the embeddable softphone; `/ws/call` refuses agent tokens). |
| `body.assistant_id` | `string` | no | The assistant the browser will talk to. |
| `body.metadata` | `MetadataInput` | no | Up to 50 key/value pairs (keys up to 40 characters, values up to 500) you attach to an object. Returned as sent. |
| `body.origin` | `string` | no | The only website the token works from (`https://shop.example`): the browser's Origin must match. Strongly recommended. http is accepted for localhost only. |
| `body.ttl_s` | `integer` | no | How long the token can be used to start the call, in seconds (300–900, default 300). The call itself may run longer. |
| `options.headers["MoreVoice-Version"]` | `string` | no | The API version to use for this request. Defaults to the version the API key is pinned to. |
| `options.headers["Idempotency-Key"]` | `string` | no | A unique key (for example a UUID) that makes this request safe to retry: for 24 hours, a retry with the same key and parameters returns the first response instead of acting twice. |
| `options` | `RequestOptions` | no | `idempotencyKey`, extra `headers` and an abort `signal`: see [retries and idempotency](https://docs.morevoice.ai/sdk/typescript/retries/). |

### Returns

`ClientToken`:

| Field | Type | Description |
| --- | --- | --- |
| `object` | `"client_token"` | Always `client_token`. |
| `token` | `string` | The client token (a signed JWT). Give it to the browser; it opens one call, once, before `expires_at`. |
| `expires_at` | `string` | An ISO-8601 timestamp in UTC. |
| `call_id` | `string` | The call the token opens (the same ID the call will have). |
| `assistant_id` | `string \| null` | `asst_…` ID. |
| `agent_user_id` | `string \| null` | `usr_…` ID. |
| `origin` | `string \| null` | The website the token is bound to, or null. |
| `livemode` | `boolean` | `true` in live mode, `false` in test mode. |
| `ws_url` | `string` | Where the browser connects: `<ws_url>?client_token=<token>` (the @morevoice/web SDK does it for you). |

### Example

```ts
import MoreVoice from "@morevoice/sdk";

const mv = new MoreVoice(); // MOREVOICE_API_KEY from the environment

const clientToken = await mv.clientTokens.create({
	assistant_id: "asst_8tRPaZp5hLMbrGqdJ9AmNa",
	metadata: {
		crm_contact_id: "0031x00000AbCdE",
	},
	origin: "https://shop.example",
	ttl_s: 300,
});
console.log(clientToken);
```
