> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replicas.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Workspace SSH Token

> Creates short-lived SSH credentials and transport details for an active workspace. This first-party endpoint requires a logged-in user JWT and the `Replicas-Org-Id` header.



## OpenAPI

````yaml /openapi.json post /v1/workspaces/{workspaceId}/ssh-token
openapi: 3.1.0
info:
  title: Replica API
  version: 2.0.0
  description: >-
    The Replica API allows you to programmatically manage cloud workspaces for
    AI agents. Use this API to manage environments (the org-scoped primitive
    workspaces are created from — including variables, files, skills, MCPs, warm
    hooks, start hooks, and warm pools), create and manage replicas, send
    messages, manage chats, stream events, read connected repositories and
    repository sets, and configure automations.
servers:
  - url: https://api.replicas.dev
    description: Production API
security:
  - apiKey: []
tags:
  - name: Environments
    description: >-
      Manage environments — the primitive that workspaces are created from.
      Variables, files, skills, MCPs, warm-hooks, and warm-pools are all scoped
      to an environment. Every organization has a singleton Global environment
      whose values apply to every workspace. Personal environments are scoped to
      the authenticated user and can be standalone or source-backed by a team
      environment.
  - name: Repository
    description: >-
      Read repositories and repository sets connected to your organization.
      Repositories are the underlying GitHub-connection layer; bind them to an
      environment to use them in workspaces.
  - name: Replica
    description: >-
      Manage replicas (workspaces) for AI agents. Workspace creation with `POST
      /v1/replica` accepts API keys and workspace engine-secret authentication.
      Other Replica operations also accept logged-in user JWTs from first-party
      clients.
  - name: Terminal
    description: Manage interactive terminal sessions in active workspaces
  - name: Tunnels
    description: Create short-lived authenticated transports to active workspaces
  - name: Preview
    description: Manage public preview URLs for workspace ports
  - name: Profile
    description: Read and update the authenticated user's profile
  - name: Credentials
    description: >-
      Manage coding-agent credentials for an organization or the authenticated
      user
  - name: Preferences
    description: Manage organization behavior preferences
  - name: Slack
    description: Connect Slack identities and route threads to Replicas workspaces
  - name: Linear
    description: Connect Linear identities to Replicas accounts
  - name: Automation
    description: >-
      Create and manage automations that trigger replicas on a schedule or in
      response to events
  - name: Downloads
    description: Download Replicas applications
  - name: Media
    description: >-
      Read workspace media and obtain short-lived download or inline preview
      URLs
  - name: Analytics
    description: >-
      Read aggregated activity and usage metrics for your organization: compute
      minutes, workspaces created by source, and pull request throughput over a
      time range.
  - name: Presence
    description: >-
      Read and report ephemeral member presence: who is online, where they are
      (environment or workspace), and whether they are typing. Presence is
      backed by short-lived keys rather than the database and broadcast to other
      members over the events stream.
  - name: Plugins
    description: >-
      Install and manage native and Composio-backed workspace plugins. A plugin
      installs for a single environment, for the whole organization (which uses
      the Global environment), or for one member personally. A workspace uses
      the most specific installation available: personal, then its own
      environment, then the environment it was branched from, then Global.
      Composio Connect Links host managed OAuth, custom OAuth, API-key,
      bearer-token, basic, and dynamic OAuth authentication without exposing
      provider credentials to Replicas.
paths:
  /v1/workspaces/{workspaceId}/ssh-token:
    post:
      tags:
        - Tunnels
      summary: Create Workspace SSH Token
      description: >-
        Creates short-lived SSH credentials and transport details for an active
        workspace. This first-party endpoint requires a logged-in user JWT and
        the `Replicas-Org-Id` header.
      operationId: createWorkspaceSshToken
      parameters:
        - name: workspaceId
          in: path
          description: Workspace UUID.
          required: true
          schema:
            type: string
            format: uuid
        - name: Replicas-Org-Id
          in: header
          description: Organization UUID containing the workspace.
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: Short-lived workspace SSH credentials
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SshTokenResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - userJwt: []
components:
  schemas:
    SshTokenResponse:
      type: object
      properties:
        token:
          type: string
          description: Short-lived token used as the SSH username.
        host:
          type: string
          description: Workspace SSH host.
        proxyCommand:
          type: string
          description: Optional OpenSSH ProxyCommand for CLI clients.
        transport:
          $ref: '#/components/schemas/SshWebSocketTransport'
      required:
        - token
        - host
    SshWebSocketTransport:
      type: object
      properties:
        type:
          type: string
          const: websocket
        url:
          type: string
          format: uri
          description: Secure WebSocket URL for the SSH transport.
        headers:
          type: object
          additionalProperties:
            type: string
          description: Provider credentials sent only during the WebSocket upgrade.
      required:
        - type
        - url
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message
        details:
          type:
            - string
            - 'null'
          description: Additional error details
        code:
          type: string
          description: Machine-readable error code when available
      required:
        - error
  responses:
    BadRequest:
      description: Bad request - Missing or invalid parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        API key authentication. Obtain your API key from the Replicas dashboard
        under Organization → Settings → API Keys.
    userJwt:
      type: http
      scheme: bearer
      description: >-
        Logged-in user-session JWT authentication for first-party clients.
        Org-scoped requests also require the `Replicas-Org-Id` header. User JWTs
        cannot create workspaces with `POST /v1/replica`.

````