> ## Documentation Index
> Fetch the complete documentation index at: https://developer.jtl-software.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint an impersonation token for a user

> Mints a token for the named user, scoped to the named tenant, on behalf of the calling app. The app authenticates with its own service-account token in the Authorization header; account-service is the exchange actor. The app must be installed for the tenant, have opted in to acting on behalf of a user, and the user must be a member of the tenant.



## OpenAPI

````yaml /openapi/account-service/token-exchange.json post /identity/act-as-user-token
openapi: 3.0.0
info:
  title: JTL Account Service - Token exchange
  version: v2
  description: >-
    Endpoints an app calls to mint and refresh delegated (act as a tenant
    install) and on-behalf-of-user (act as a user) tokens via RFC 8693 token
    exchange.
servers:
  - url: https://api.jtl-cloud.com/account
    description: Production
  - url: https://api.qa.jtl-cloud.com/account
    description: QA
  - url: https://api.dev.jtl-cloud.com/account
    description: Development
security: []
paths:
  /identity/act-as-user-token:
    post:
      tags:
        - Identity
      summary: Mint an impersonation token for a user
      description: >-
        Mints a token for the named user, scoped to the named tenant, on behalf
        of the calling app. The app authenticates with its own service-account
        token in the Authorization header; account-service is the exchange
        actor. The app must be installed for the tenant, have opted in to acting
        on behalf of a user, and the user must be a member of the tenant.
      operationId: ActAsUserToken
      requestBody:
        x-name: ActAsUserTokenRequest
        description: ''
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ActAsUserTokenRequest'
        required: true
        x-position: 1
      responses:
        '200':
          description: The user-subject access token, its refresh token and lifetime.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActAsUserTokenResponse'
        '401':
          description: No bearer token was presented.
        '403':
          description: >-
            The caller carries no app id, is not installed or opted in, or the
            user is not in the tenant.
      security:
        - JWTBearerAuth: []
components:
  schemas:
    ActAsUserTokenRequest:
      type: object
      description: >-
        Represents a request to mint an impersonation token for a user on behalf
        of the calling app. The app

        authenticates with its own service-account token in the Authorization
        header (identified by its

        urn:jtl:app_id claim); no user token is needed.
      additionalProperties: false
      required:
        - userId
        - tenantId
      properties:
        userId:
          type: string
          description: >-
            Gets or sets the Zitadel user id to impersonate (the subject of the
            minted token).
          minLength: 1
        tenantId:
          type: string
          description: >-
            Gets or sets the tenant to act in. The app must be installed for it
            and the user must be a member

            of it; the minted token is stamped with this tenant.
          minLength: 1
    ActAsUserTokenResponse:
      type: object
      description: Represents the response for a minted on-behalf-of-user token.
      additionalProperties: false
      properties:
        accessToken:
          type: string
          description: Gets the user-subject access token minted for the calling app.
        refreshToken:
          type: string
          description: >-
            Gets the refresh token for rotating the access token for unattended,
            long-running access.
          nullable: true
        expiresIn:
          type: number
          description: Gets the access token lifetime in seconds.
          format: double
  securitySchemes:
    JWTBearerAuth:
      type: http
      description: Enter a JWT token to authorize the requests...
      scheme: Bearer
      bearerFormat: JWT

````