## Authenticate with a temporary token

If you need to authenticate on the client, you can avoid exposing your API key by using temporary authentication tokens. You should generate this token on your server and pass it to the client.

### GET

`/v3/token`

### cURL

```bash
curl -G https://streaming.assemblyai.com/v3/token \
     -H "Authorization: <apiKey>" \
     -d expires_in_seconds=60
```

[Try it](/content/docs/api-reference/streaming-api/generate-streaming-token?explorer=true/index.html)

### Python

To generate a temporary token, make a `POST` request to the temporary [token endpoint](/content/docs/api-reference/streaming-api/generate-streaming-token/index.html).

Use the `expires_in_seconds` parameter to specify the duration for which the token will remain valid. Optionally, use the `max_session_duration_seconds` parameter to specify the desired maximum duration for the session initialized using this token.

```python
import requests
from urllib.parse import urlencode

def create_temporary_token():
    url = "https://streaming.assemblyai.com/v3/token"
    response = requests.get(
        f"{url}?{urlencode({'expires_in_seconds': 60})}",
        headers={"Authorization": "<YOUR_API_KEY>"},
    )
    data = response.json()
    return data.get("token")
```

`expires_in_seconds` must be a value between `1` and `600` seconds. If specified, `max_session_duration_seconds` must be a value between `60` and `10800` seconds (defaults to maximum session duration of 3 hours).

The client should retrieve the token from the server and use the token to authenticate the transcriber.

Each token has a one-time use restriction and can only be used for a single session. Any usage associated with a temporary token will be attributed to the API key that generated it.

### To use it

Specify the `token` parameter as a query parameter in the WebSocket URL.

```python
params_w_token = {**CONNECTION_PARAMS, "speech_model": "u3-rt-pro", "token": token}
ws_app = websocket.WebSocketApp(
    f'{API_ENDPOINT_BASE_URL}?{urlencode(params_w_token)}',
    on_open=on_open,
    on_message=on_message,
    on_error=on_error,
    on_close=on_close,
)
```
