---
title: Create OneShot Security Token
slug: api/create-oneshot-security-token
docTags: 
createdAt: 2026-09-23T02:36:41.274Z
---

{
  "id": "wkvVgeX_jFLXp6k2g4A_L",
  "type": "api-oas-v2",
  "data": {
    "method": "GET",
    "url": "https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}",
    "servers": [
      {
        "url": "https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}",
        "description": "Production"
      },
      {
        "url": "https://api.m-pay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}",
        "description": "Sandbox"
      }
    ],
    "name": "Create OneShot Security Token",
    "description": "<p>This API returns a security token that can be used only once or until it expires. The purpose of this token is that it can be embedded in a web form to enable you to make a single call to the Engine without exposing your Sign-In Account credentials. When setting your security credentials to call any of the APIs in this document (except for security/v1/createOneShotSecurityToken), set the Username to the returned OneShotSecurityToken and set the password to anything as it will be ignored.</p>",
    "contentType": "application/json",
    "request": {
      "pathParameters": [
        {
          "kind": "required",
          "name": "timeOutMin",
          "type": "string",
          "example": "15",
          "description": "<p><strong>Required</strong> — The number of whole minutes before the returned token expires. Each token has an expiry time between 1 and 15 minutes. Values outside this range are rejected with a 400 response.</p>",
          "default": "15",
          "pattern": "^([1-9]|1[0-5])$"
        }
      ],
      "headerParameters": [
        {
          "name": "accept",
          "type": "string",
          "kind": "optional",
          "description": "Generated from available response content types",
          "enum": [
            "application/json"
          ],
          "default": "application/json"
        }
      ],
      "queryParameters": [],
      "bodyDataParameters": [],
      "formDataParameters": [],
      "oAuthParameters": [
        {
          "id": "basicAuth",
          "name": "basicAuth",
          "kind": "optional",
          "type": "http",
          "description": "<p>To authenticate using basic authentication, generate an API key and pass it as the username. No password is required.</p>",
          "scheme": "basic"
        }
      ],
      "cookieParameters": []
    },
    "responses": [
      {
        "statusCode": "200",
        "description": "successful validation",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"oneShotSecurityToken\":\"8f4c2b7a3d194e6c9f285b7e1a0c6d34\",\"durationMs\":21,\"status\":\"Ok\",\"statusDescription\":\"Operation completed successfully\"}",
            "description": "<p>The single-use security token issued by the Engine, returned with the standard status envelope.</p>",
            "customType": "CreateOneShotSecurityTokenResponse_V1",
            "schema": [
              {
                "name": "oneShotSecurityToken",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — The token to use instead of UserName. The token can be used once, or until it expires, whichever happens first. Pass it as the basic authentication username on the next call and set the password to any value, as it is ignored.</p>",
                "example": "8f4c2b7a3d194e6c9f285b7e1a0c6d34",
                "default": "8f4c2b7a3d194e6c9f285b7e1a0c6d34",
                "pattern": "^[A-Za-z0-9+/=_-]{16,512}$"
              },
              {
                "name": "durationMs",
                "kind": "required",
                "type": "integer<int64>",
                "description": "<p><strong>Required</strong> — This value represents the total time in milliseconds that the Platform took to process the request.</p>",
                "example": 21,
                "default": 21,
                "format": "int64",
                "pattern": "^[0-9]{1,19}$"
              },
              {
                "name": "status",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — This is the status of the request. A code of 'Ok' indicates no errors. Any other value indicates that the request was not completed successfully.</p>",
                "example": "Ok",
                "default": "Ok",
                "pattern": "^[A-Za-z]{1,50}$"
              },
              {
                "name": "statusDescription",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — This is a description of the status. If an 'Ok' status is returned, then this will be 'Operation completed successfully'.</p>",
                "example": "Operation completed successfully",
                "default": "Operation completed successfully",
                "pattern": "^.{0,500}$"
              }
            ],
            "modelRef": "#/components/schemas/CreateOneShotSecurityTokenResponse_V1",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "400",
        "description": "<p>Bad request — the request could not be validated. Check that every required parameter is supplied and that each value matches the documented pattern.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"durationMs\":12,\"status\":\"Error\",\"statusDescription\":\"The request is invalid. One or more parameters are missing or do not match the expected format.\"}",
            "description": "Standard error envelope returned by the Security API when a request cannot be completed.",
            "customType": "ErrorResponse_V1",
            "schema": [
              {
                "name": "durationMs",
                "kind": "required",
                "type": "integer<int64>",
                "description": "<p><strong>Required</strong> — This value represents the total time in milliseconds that the Platform took to process the request before it failed.</p>",
                "example": 12,
                "default": 12,
                "format": "int64",
                "pattern": "^[0-9]{1,19}$"
              },
              {
                "name": "status",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — The status code of the failed request. Any value other than 'Ok' indicates that the request was not processed.</p>",
                "example": "Error",
                "default": "Error",
                "pattern": "^[A-Za-z]{1,50}$"
              },
              {
                "name": "statusDescription",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — A human readable description of why the request failed. Use this value when logging or surfacing the error to an operator.</p>",
                "example": "The request could not be processed. See statusDescription for details.",
                "default": "The request could not be processed. See statusDescription for details.",
                "pattern": "^.{0,500}$"
              }
            ],
            "modelRef": "#/components/schemas/ErrorResponse_V1",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "401",
        "description": "<p>Unauthorized — the API key passed as the basic authentication username is missing, invalid, or the Sign-In Account does not have permission to call this endpoint. After five consecutive failures on the live Engine the Sign-In Account is locked for one hour.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "headers": [
          {
            "kind": "optional",
            "name": "WWW-Authenticate",
            "type": "string",
            "example": "Basic",
            "description": "Indicates the authentication scheme expected by the Engine."
          }
        ],
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"durationMs\":8,\"status\":\"Unauthorized\",\"statusDescription\":\"Authentication failed. Supply a valid API key as the basic authentication username.\"}",
            "description": "Standard error envelope returned by the Security API when a request cannot be completed.",
            "customType": "ErrorResponse_V1",
            "schema": [
              {
                "name": "durationMs",
                "kind": "required",
                "type": "integer<int64>",
                "description": "<p><strong>Required</strong> — This value represents the total time in milliseconds that the Platform took to process the request before it failed.</p>",
                "example": 12,
                "default": 12,
                "format": "int64",
                "pattern": "^[0-9]{1,19}$"
              },
              {
                "name": "status",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — The status code of the failed request. Any value other than 'Ok' indicates that the request was not processed.</p>",
                "example": "Error",
                "default": "Error",
                "pattern": "^[A-Za-z]{1,50}$"
              },
              {
                "name": "statusDescription",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — A human readable description of why the request failed. Use this value when logging or surfacing the error to an operator.</p>",
                "example": "The request could not be processed. See statusDescription for details.",
                "default": "The request could not be processed. See statusDescription for details.",
                "pattern": "^.{0,500}$"
              }
            ],
            "modelRef": "#/components/schemas/ErrorResponse_V1",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "500",
        "description": "<p>Internal server error — an unexpected error occurred while the Engine was processing the request. The request should be retried; if the error persists, contact Monoova support.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"durationMs\":35,\"status\":\"Exception\",\"statusDescription\":\"An unexpected error occurred while processing the request. Please retry or contact support.\"}",
            "description": "Standard error envelope returned by the Security API when a request cannot be completed.",
            "customType": "ErrorResponse_V1",
            "schema": [
              {
                "name": "durationMs",
                "kind": "required",
                "type": "integer<int64>",
                "description": "<p><strong>Required</strong> — This value represents the total time in milliseconds that the Platform took to process the request before it failed.</p>",
                "example": 12,
                "default": 12,
                "format": "int64",
                "pattern": "^[0-9]{1,19}$"
              },
              {
                "name": "status",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — The status code of the failed request. Any value other than 'Ok' indicates that the request was not processed.</p>",
                "example": "Error",
                "default": "Error",
                "pattern": "^[A-Za-z]{1,50}$"
              },
              {
                "name": "statusDescription",
                "kind": "required",
                "type": "string",
                "description": "<p><strong>Required</strong> — A human readable description of why the request failed. Use this value when logging or surfacing the error to an operator.</p>",
                "example": "The request could not be processed. See statusDescription for details.",
                "default": "The request could not be processed. See statusDescription for details.",
                "pattern": "^.{0,500}$"
              }
            ],
            "modelRef": "#/components/schemas/ErrorResponse_V1",
            "isExpanded": true
          }
        ]
      }
    ],
    "hasXCodeSamples": false,
    "examples": {
      "languages": [
        {
          "id": "HIckB02NEfryatttX3652",
          "language": "curl",
          "label": "cURL",
          "code": "curl --request GET \\\n     --url https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin} \\\n     --header 'accept: application/json'"
        },
        {
          "id": "idT0Lm1Geh9bpa-GLM91F",
          "language": "javascript",
          "label": "javascript",
          "code": "var myHeaders = new Headers();\nmyHeaders.append(\"accept\", \"application/json\");\nmyHeaders.append(\"content-type\", \"application/json\");\n\nvar requestOptions = {\n   method: 'GET',\n   headers: myHeaders,\n   redirect: 'follow'\n};\n\nfetch(\"https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}\", requestOptions)\n   .then(response => response.text())\n   .then(result => console.log(result))\n   .catch(error => console.log('error', error));"
        },
        {
          "id": "84usbV_sJrciWSMvJDj-4",
          "language": "ruby",
          "label": "Ruby",
          "code": "require \"uri\"\nrequire \"json\"\nrequire \"net/http\"\n\nurl = URI(\"https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}\")\n\nhttps = Net::HTTP.new(url.host, url.port)\nhttps.use_ssl = true\n\nrequest = Net::HTTP::Get.new(url)\nrequest[\"accept\"] = \"application/json\"\nrequest[\"content-type\"] = \"application/json\"\n\nresponse = https.request(request)\nputs response.read_body\n"
        },
        {
          "id": "8QC6nruDCvv7zqrCCaxcM",
          "language": "python",
          "label": "Python",
          "code": "import requests\nimport json\n\nurl = \"https://api.mpay.com.au/security/v1/createOneShotSecurityToken/{timeOutMin}\"\n\npayload = {}\nheaders = {\n   'accept': 'application/json',\n   'content-type': 'application/json'\n}\n\nresponse = requests.request(\"GET\", url, headers=headers, data=payload)\n\nprint(response.text)\n"
        }
      ],
      "selectedLanguageId": "HIckB02NEfryatttX3652"
    },
    "results": {
      "languages": [
        {
          "id": "e5rR-hKgm40NvDPVBVmJn",
          "language": "200",
          "code": "// successful validation\n{\n  \"oneShotSecurityToken\": \"8f4c2b7a3d194e6c9f285b7e1a0c6d34\",\n  \"durationMs\": 21,\n  \"status\": \"Ok\",\n  \"statusDescription\": \"Operation completed successfully\"\n}"
        },
        {
          "id": "_q62mjGYgwei945K6OMmy",
          "language": "400",
          "code": "// Bad request — the request could not be validated. Check that every required parameter is supplied and that each value matches the documented pattern.\n{\n  \"durationMs\": 12,\n  \"status\": \"Error\",\n  \"statusDescription\": \"The request could not be processed. See statusDescription for details.\"\n}"
        },
        {
          "id": "2oNlzOPN3mc0FQ_rnIhOd",
          "language": "401",
          "code": "// Unauthorized — the API key passed as the basic authentication username is missing, invalid, or the Sign-In Account does not have permission to call this endpoint. After five consecutive failures on the live Engine the Sign-In Account is locked for one hour.\n{\n  \"durationMs\": 12,\n  \"status\": \"Error\",\n  \"statusDescription\": \"The request could not be processed. See statusDescription for details.\"\n}"
        },
        {
          "id": "33UwO2Kt15gi_AzupQtyP",
          "language": "500",
          "code": "// Internal server error — an unexpected error occurred while the Engine was processing the request. The request should be retried; if the error persists, contact Monoova support.\n{\n  \"durationMs\": 12,\n  \"status\": \"Error\",\n  \"statusDescription\": \"The request could not be processed. See statusDescription for details.\"\n}"
        }
      ],
      "selectedLanguageId": "e5rR-hKgm40NvDPVBVmJn"
    }
  },
  "children": [
    {
      "text": ""
    }
  ]
}