Create Access Token
Exchange a credential for an access token. Supports two grant types:
authorization_code: Exchange an authorization code for an access token (cross-org data sharing).client_credentials: Exchange a signed JWT assertion (private_key_jwt) for a short-lived access token (machine-to-machine auth, RFC 7523).
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
Request
Exchange a signed JWT assertion for a short-lived access token. The JWT must be signed with the private key corresponding to the public key registered on the OAuth client. Note: parameter names follow OAuth RFC 6749/7523 conventions (snake_case) rather than the Persona API default (kebab-case).
Response headers
The maximum number of requests permitted in the current rate limit window. For an API key with its own rate limit, requests count against both the key's limit and the environment's limit, and this header reports whichever is closer to being reached, so it can change between responses. On a 429 response, it reports the limit that rejected the request. For an API key without its own rate limit, it reports the environment's limit. Returned on every authenticated response.
The number of requests remaining in the current rate limit window for the limit reported in RateLimit-Limit. Returned on every authenticated response.
The unique identifier of the API log entry that recorded this request. Starts with req_. Include this value when reaching out to Persona support. Present on every authenticated response, including error responses.
Response
Space-separated list of granted permissions. Format varies by grant type: for client_credentials, bare permission names (e.g. inquiry.read account.read); for authorization_code, permission:object pairs (e.g. inquiry.read:inq_xxx). Empty string when no permissions are granted.

