> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anny.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create connection token

> Creates a short-lived Stripe Terminal SDK connection token.

Pass the returned `secret` to the Stripe Terminal SDK's `fetchToken` callback to initialize a terminal session. Tokens are **single-use and short-lived** — always request a fresh token; never cache.

If no `payment-account` relationship is provided, the organization's default payment account is used. Optionally scope the token to a specific location via the `location` relationship.

**SDK initialization example (Dart):**
```dart
await StripeTerminal.instance.initialize(
  fetchToken: () async {
    final res = await dio.post('/api/v1/connection-tokens', data: {
      'data': {'type': 'connection-tokens', 'attributes': {}},
    });
    return res.data['data']['attributes']['secret'];
  },
);
```




## OpenAPI

````yaml /developers/openapi/admin-internal.openapi.json post /api/v1/connection-tokens
openapi: 3.1.0
info:
  title: admin-api
  version: '1.0'
  description: >-
    The Admin API gives you **full programmatic access** to your anny
    organization. It is built for **server-side integrations** — backend
    services, automation scripts, and custom tooling that act on behalf of your
    team.


    ---


    ## When to use the Admin API


    Use the Admin API when you need to **drive workflows from your own
    systems**:


    - **Sync membership data** — create or update customers, assign them to
    communities, reflect subscription status from an external CRM

    - **Create bookings programmatically** — build back-office tools or automate
    repeat reservations without going through the customer checkout

    - **Issue and forward invoices** — generate invoices, send them to
    customers, or push them to your accounting system

    - **React to real-time events** — pair the API with
    [Webhooks](/developers/guides/admin/webhooks) to trigger side effects
    whenever a booking is created, cancelled, or checked in

    - **Drive display panels** — push live occupancy and schedule data to
    digital signage or lobby displays


    Combined with [webhook subscriptions](/developers/guides/admin/webhooks),
    you can build fully automated, event-driven workflows without polling.


    ---


    ## Authentication


    Generate a long-lived API token directly in the admin dashboard under
    **Organization Settings → API**. All requests require it in the
    `Authorization` header:


    ```

    Authorization: Bearer {access_token}

    ```


    Every endpoint is **organization-scoped**. Pass your organization ID as a
    query parameter on every request:


    ```

    ?o={organization_id}

    ```


    See the [Authentication guide](/developers/guides/authentication) for token
    scopes and the full OAuth2 flow.


    ---


    ## Admin API vs Customer API


    | | Admin API | Customer API |

    |---|---|---|

    | **Use case** | Server-side automation, backend tooling | End-user apps,
    booking widgets |

    | **Auth** | Required — API token or OAuth2 | Optional — many endpoints work
    without a token |

    | **Identifiers** | Immutable UUIDs and integer IDs | Slugs, booking
    numbers, order numbers |

    | **Access** | Full read/write | Public and customer-owned data only |


    → [Go to the Customer API](/developers/api-reference/customer)


    ---


    ## Resource Identifiers


    The Admin API uses **immutable IDs** — UUIDs for most entities, integers for
    legacy ones. These are safe to store in external systems and never change,
    even if an organization renames a resource.


    ---


    ## Starting Points


    | Guide | What it covers |

    |---|---|

    | [Getting Started](/developers) | First steps and quickstart |

    | [JSON:API Conventions](/developers/guides/json-api-conventions) | Request
    and response format |

    | [Authentication](/developers/guides/authentication) | API tokens, OAuth2,
    scopes |

    | [Availability & Booking Search](/developers/guides/availability) | Search
    open slots and timeslots |

    | [Admin Booking Creation](/developers/guides/admin/booking-creation) |
    Create bookings from the back office |

    | [Admin Booking Edit](/developers/guides/admin/booking-edit) | Edit
    resource, dates, fields, add-ons, and sub-bookings |

    | [Admin Booking Lifecycle](/developers/guides/admin/booking-lifecycle) |
    Status changes, check-in, cancellations |

    | [Invoices](/developers/guides/admin/invoices) | Create, send, and manage
    invoices |

    | [Customer Management](/developers/guides/admin/customer-management) |
    Create and manage customer records |

    | [Booking Calendars](/developers/guides/admin/calendar-events) | Custom
    calendar events |

    | [Timeslot Management](/developers/guides/admin/timeslot-management) |
    Manage timeslot CRUD, recurrence, allocations, and rescheduling |

    | [Broadcast Campaigns](/developers/guides/admin/broadcasting) | Email and
    push campaigns |

    | [Exports](/developers/guides/admin/exports) | Export bookings and customer
    data |

    | [Webhooks & Events](/developers/guides/admin/webhooks) | Subscribe to
    real-time events |


    ---


    ## Base URLs


    | Environment | URL |

    |---|---|

    | Production | `https://b.anny.co` |

    | Gov-Cloud | `https://b.anny.eu` |
  contact:
    name: anny GmbH
    url: https://anny.co
    email: support@anny.co
servers:
  - url: https://b.anny.co
    description: Production
  - url: https://b.anny.eu
    description: Gov-Cloud
security:
  - Bearer: []
tags:
  - name: Booking Quotas
  - name: Orders
  - name: Organizations
  - name: Table Configuration
  - name: Test-Results
  - name: User Settings
  - name: Terminal Locations
  - name: Terminal Readers
  - name: Connection Tokens
  - name: Views
  - name: Voice Integration
paths:
  /api/v1/connection-tokens:
    post:
      tags:
        - Connection Tokens
      summary: Create connection token
      description: >
        Creates a short-lived Stripe Terminal SDK connection token.


        Pass the returned `secret` to the Stripe Terminal SDK's `fetchToken`
        callback to initialize a terminal session. Tokens are **single-use and
        short-lived** — always request a fresh token; never cache.


        If no `payment-account` relationship is provided, the organization's
        default payment account is used. Optionally scope the token to a
        specific location via the `location` relationship.


        **SDK initialization example (Dart):**

        ```dart

        await StripeTerminal.instance.initialize(
          fetchToken: () async {
            final res = await dio.post('/api/v1/connection-tokens', data: {
              'data': {'type': 'connection-tokens', 'attributes': {}},
            });
            return res.data['data']['attributes']['secret'];
          },
        );

        ```
      operationId: create-connection-token
      parameters:
        - schema:
            type: string
          in: query
          name: o
          description: Organization ID
      requestBody:
        required: true
        content:
          application/vnd.api+json:
            schema:
              type: object
              required:
                - data
              properties:
                data:
                  type: object
                  required:
                    - type
                  properties:
                    type:
                      type: string
                      default: connection-tokens
                    attributes:
                      type: object
                      description: No attributes required
                    relationships:
                      type: object
                      properties:
                        payment-account:
                          type: object
                          description: >-
                            Explicit payment account. Defaults to the
                            organization's primary account.
                          properties:
                            data:
                              type: object
                              properties:
                                type:
                                  type: string
                                  default: payment-accounts
                                id:
                                  type: string
                                  format: uuid
                        location:
                          type: object
                          description: >-
                            Scope the connection token to a specific terminal
                            location.
                          properties:
                            data:
                              type: object
                              properties:
                                type:
                                  type: string
                                  default: terminal-locations
                                id:
                                  type: string
                                  format: uuid
            examples:
              minimal:
                summary: Minimal (uses org default account)
                value:
                  data:
                    type: connection-tokens
                    attributes: {}
              with_location:
                summary: Scoped to a specific location
                value:
                  data:
                    type: connection-tokens
                    attributes: {}
                    relationships:
                      location:
                        data:
                          type: terminal-locations
                          id: 00000000-0000-0000-0000-000000000000
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      type:
                        type: string
                        default: connection-tokens
                      attributes:
                        type: object
                        properties:
                          secret:
                            type: string
                            description: Single-use Stripe Terminal SDK connection secret
                            example: pst_test_abc123
        '400':
          description: Bad Request — payment account missing or terminal not supported
        '401':
          description: Unauthorized
      security:
        - Bearer: []
components:
  securitySchemes:
    Bearer:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: https://auth.anny.co/oauth/authorize
          tokenUrl: https://auth.anny.co/oauth/token
          refreshUrl: https://auth.anny.co/oauth/token/refresh
          scopes: {}

````