# Mint a single-use connect URL for /v1/browser (coming soon)

> Returns a `/v1/browser` URL that carries a short-lived token instead of the API key, for CDP clients that accept only a URL.

Source: https://docs.spicrawl.com/api-reference/browser/browser-token

## POST /v1/browser/token

Operation ID: `browserToken`. API key scope: `browser`.

Coming soon.
Returns a `/v1/browser` URL that carries a short-lived token instead of the API key, for CDP clients
that accept only a URL. The key goes in the `Authorization` header of THIS request only (a query key
is refused). The token is single-use, expires after 60 s, and is bound to the options in the body:
connect with the URL unchanged. `path` is authoritative: the URL relative to the API base. `url` is
built from the deployment's SPICRAWL_BROWSER_PUBLIC_URL when set, otherwise from this request's scheme and
Host header (caller-controlled, a convenience only). The token is
never logged and never stored in plaintext. Requires the `browser` scope.

### Example

```bash
curl -X POST "https://api.spicrawl.com/v1/browser/token" \
  -H "Authorization: Bearer $SPICRAWL_API_KEY"
```

### Request body

`application/json`.

| Field | Type | Required | Description |
|---|---|---|---|
| `engine` | string: `chromium`, `obscura` | no |  |
| `proxy_country` | string | no |  |
| `proxy_region` | string | no |  |
| `sticky_key` | string | no |  |
| `session_ttl` | integer | no |  |
| `headless` | boolean | no |  |

### Responses

#### 200

The connect URL, sent with Cache-Control no-store.

`application/json`.

| Field | Type | Required | Description |
|---|---|---|---|
| `url` | string | yes |  |
| `path` | string | yes |  |
| `expires_at` | string (date-time) | yes |  |
| `expires_in` | integer | yes |  |
| `single_use` | boolean | yes |  |

#### 400

The request is invalid. Not retryable; fix the request using `code` and `diagnostics.hint`.

Headers: `X-Request-Id`.

`application/problem+json` (`Problem` schema).

#### 401

Missing, invalid, revoked or expired key. Not retryable with the same key.

Headers: `X-Request-Id`.

`application/problem+json` (`Problem` schema).

#### 403

The key lacks the scope this route requires (`ERR::AUTH::INSUFFICIENT_SCOPE`), or the action is not permitted.

Headers: `X-Request-Id`.

`application/problem+json` (`Problem` schema).

#### 503

No proxy exit or engine capacity was available. Retryable after `Retry-After`; 0 credits.

Headers: `Retry-After`, `X-Request-Id`.

`application/problem+json` (`Problem` schema).

Full OpenAPI spec: https://docs.spicrawl.com/openapi.yaml
