> This page is for version v2026-04-01 (default).
> For other versions, use one of these documentation indexes:
> - v2026-04-01 (default): https://docs.givechariot.com/v2026-04-01/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.givechariot.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.givechariot.com/_mcp/server.

# Create Authorization Token

POST https://api.givechariot.com/v1/donor_accounts/{id}/authorization_tokens
Content-Type: application/json

Create a single-use Authorization Token bound to a Donor Account.

Authorization Tokens are the binding credential used to verify a donor's identity between DAFpay and the DAF.
They are used in two distinct flows:

* **DAF-Initiated Setup**: The DAF creates a Donor Account and then creates an Authorization Token. The DAF surfaces the token's `code` to the donor via their portal. The donor enters the `code` into DAFpay during profile setup, automatically approving the Donor Account.
* **Donor-Initiated Verification**: After a donor submits a Grant Request, DAFpay automatically issues an Authorization Token and emails the `code` to the donor. The donor provides the `code` to the DAF (e.g. via a portal form or phone call). The DAF then calls [Verify Authorization Token](/api/authorization-tokens/verify) with the `code` to verify and approve the linked Donor Account.

Tokens expire **30 days** after creation by default. Override the lifetime by passing `expires_in` (seconds) on the request body — supported range is 60 seconds to 90 days. Once a token expires it transitions to `expired` and can no longer be verified; create a new token to issue a fresh code.

The token's `code` value is **only returned once** in this response. Treat it as a credential — store it securely and never log it. If the code is lost before being verified, [revoke](/api/authorization-tokens/revoke) the token and create a new one.

Reference: https://docs.givechariot.com/api/authorization-tokens/create

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.givechariot.com` (Production, default)
- `https://sandboxapi.givechariot.com` (Sandbox)

## Request

### Path parameters

- `id` (string, required) — The unique id of the Donor Account

### Body (application/json)

This endpoint expects an object.

- `expires_in` (integer, optional) — The number of seconds the token is valid for. Defaults to 30 days. Must be between 60 (1 minute) and 7,776,000 (90 days).
- `metadata` (map from string to string, optional) — A map of arbitrary string keys and values to store information about the object.

## Response

### 201

Created

- `id` (string, required) — The unique identifier for this object.
- `donor_account_id` (string, required) — The ID of the [Donor Account](/api/donor-accounts) this token is bound to.
- `status` (enum, required) — The status of a [Donor Authorization Token](/api/authorization-tokens). * `pending`: The token has been issued but not yet verified. * `verified`: The token has been verified and can no longer be used. * `revoked`: The token was explicitly revoked before being verified. * `expired`: The token's `expires_at` has passed and it can no longer be verified.
  - Allowed values: `pending`, `verified`, `revoked`, `expired`
- `created_at` (datetime, required) — Time when the token was issued. Expressed in RFC 3339 format.
- `expires_at` (datetime, required) — Time at which this token will expire and can no longer be verified. Defaults to 30 days after creation; configurable via the `expires_in` parameter on [Create Authorization Token](/api/authorization-tokens/create).
- `code` (string, optional) — The token's secret code value. The `code` is **only returned in the response of [Create Authorization Token](/api/authorization-tokens/create)**. It is omitted from all other responses (Get, List). If the code is lost, [revoke](/api/authorization-tokens/revoke) the token and create a new one. The format is a 12-character alphanumeric string designed to be easy for donors to read aloud or copy. Codes are not case-sensitive when verified.
- `verified_at` (datetime, optional) — Time at which the token was verified. Only set when `status` is `verified`.
- `revoked_at` (datetime, optional) — Time at which the token was revoked. Only set when `status` is `revoked`.
- `metadata` (map from string to string, optional) — A map of arbitrary string keys and values to store information about the object.

## Errors

### 400 Bad Request Error

The request is invalid or contains invalid parameters

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 401 Unauthorized Error

Unauthorized. The request is missing the security (OAuth2 Bearer token) requirements and the server is unable to verify the identify of the caller.

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 403 Forbidden Error

Access denied

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 404 Not Found Error

Resource Not Found

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

### 500 Internal Server Error

Internal Server Error

- `type` (string, required) — A URI reference identifying the problem type.
- `title` (string, required) — A short, human-readable summary of the problem type.
- `status` (integer, required) — The HTTP status code for this error.
- `detail` (string, required) — A human-readable explanation specific to this occurrence.

## Examples

**Request**

```json
{}
```

**Response**

```json
{
  "id": "auth_token_01jpjenf5q6cawy43yxfcrxhct",
  "donor_account_id": "donor_account_01jpjenf5q6cawy43yxfcrxhct",
  "status": "pending",
  "created_at": "2026-04-01T12:00:00Z",
  "expires_at": "2026-05-01T12:00:00Z",
  "code": "DAFP-7K3X-9M4Q"
}
```