curl --request POST \
--url https://api.gigstack.io/v2/teams/{id}/portal-access-token \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiresIn": "1h",
"scopes": [
"invoices:read"
]
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expiresIn: '1h', scopes: ['invoices:read']})
};
fetch('https://api.gigstack.io/v2/teams/{id}/portal-access-token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/teams/{id}/portal-access-token"
payload = {
"expiresIn": "1h",
"scopes": ["invoices:read"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.<payload>.<signature>",
"url": "https://embeded.gigstack.pro/facturas?t=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.%3Cpayload%3E.%3Csignature%3E",
"expiresAt": "2026-01-08T00:00:00.000Z"
}{
"error": "invalid_expires_in",
"message": "expiresIn cannot exceed 24h"
}{
"error": "forbidden_team",
"message": "The requested team does not belong to your account"
}{
"success": false,
"error": {
"code": "resource_not_found",
"message": "Resource not found"
},
"timestamp": 1767225600000
}Create a portal access token
Mint a short-lived, read-only access token for the team’s public portal, and get a ready-to-share magic link.
The link opens the gigstack public portal (embeded.gigstack.pro) where the team can list and download its issued live-mode invoices, branded with your master team’s logo and colors. The token cannot create, modify or cancel anything, and it only grants the scopes you request.
Important: Minting a token for a team other than your own is only available for gigstack Connect accounts (master teams), and the target team must belong to your billing account.
Use Cases
- Embed an “invoices” section for your sub-teams inside your own product
- Generate on-demand links so a sub-team can review its issued invoices without a gigstack login
Recommendations
- Generate the link at click time and redirect the user to it; do not store it or send it by email
- Use the default 1h expiry unless you have a longer-lived embedded session
curl --request POST \
--url https://api.gigstack.io/v2/teams/{id}/portal-access-token \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"expiresIn": "1h",
"scopes": [
"invoices:read"
]
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({expiresIn: '1h', scopes: ['invoices:read']})
};
fetch('https://api.gigstack.io/v2/teams/{id}/portal-access-token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.gigstack.io/v2/teams/{id}/portal-access-token"
payload = {
"expiresIn": "1h",
"scopes": ["invoices:read"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.<payload>.<signature>",
"url": "https://embeded.gigstack.pro/facturas?t=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.%3Cpayload%3E.%3Csignature%3E",
"expiresAt": "2026-01-08T00:00:00.000Z"
}{
"error": "invalid_expires_in",
"message": "expiresIn cannot exceed 24h"
}{
"error": "forbidden_team",
"message": "The requested team does not belong to your account"
}{
"success": false,
"error": {
"code": "resource_not_found",
"message": "Resource not found"
},
"timestamp": 1767225600000
}Authorizations
Authentication Method: HTTP Bearer token.
The runtime requires the literal Bearer prefix — a bare token in the
Authorization header is rejected with 401 unauthorized.
Header Format: Authorization: Bearer YOUR_API_KEY
Your API key is a JWT. Live keys operate on live data (livemode: true);
test keys operate on isolated test data (livemode: false).
Get your key at: app.gigstack.pro/settings?tab=api
Errors: credential failures are answered by the authentication layer with a raw
{ "message": … } body, not the standardized envelope — 401 for a missing, malformed or
expired token, 403 for a revoked key or a plan without API access. See the Unauthorized
and AuthForbidden responses.
Path Parameters
Team ID to mint the portal access token for
Query Parameters
gigstack Connect: Target team ID for multi-team access.
Requires gigstack Connect enabled on your team and shared billing account.
Also requires the multipleIssuerAccounts feature on your plan. Requests targeting a
team other than the one your API key belongs to return 403 without it.
Only API keys can use it: an OAuth access token sent with another team's id is rejected with
403 Team mismatch with OAuth token.
Optional — omit it entirely unless you are acting on another team. It deliberately
carries no example value so generated snippets do not emit ?team=undefined; when the
parameter is absent, the team is derived from your API key.
Example: ?team=team_xyz789
Body
Response
Portal access token created successfully