# Create an Access Token

Generate a short-lived Access Token (JWT) to authenticate Hero Health Elements (SDKs).
**Important:** This endpoint must only be called from your server — never from client-side code. The returned token expires after 30 minutes.
Use the returned `access_token` as the `jwt-token` attribute when rendering a Hero Element (React component or Web Component).
Admin attribution on the newly created token is resolved from:
- `x-admin-id` on token generation (header)
- the default-admin behaviour: falls back to the practice group's configured default admin when the header is not supplied.

Endpoint: POST /v1/access_token
Version: 1.0.0
Security: apiKeyAuth, practiceGroupId

## Security:

  - `apiKeyAuth` (unknown)
    apiKey in header x-api-key

  - `practiceGroupId` (unknown)
    apiKey in header x-practice-group-id

## Response 200:

  - `200` (unknown)
    Ok

## Response 200 fields (application/json):

  - `access_token` (string, required)

## Response 401:

  - `401` (unknown)
    Unauthorised — invalid or missing API key

## Response 401 fields (application/json):

  - `error` (boolean, required)
    Example: true

  - `statusCode` (number, required)
    Example: 401

  - `message` (string, required)
    Example: Invalid or missing API key

## Response 403:

  - `403` (unknown)
    Forbidden — API key does not have the required scope

## Response 429:

  - `429` (unknown)
    Too Many Requests

## Response 500:

  - `500` (unknown)
    Unknown error

