> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useanima.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Post extensionexchange



## OpenAPI

````yaml /openapi.json post /extension/exchange
openapi: 3.1.1
info:
  title: Anima API
  version: 0.1.0
  description: >-
    The Anima API provides programmatic access to unified infrastructure for AI
    agents: create and manage agents; send and receive email; place phone calls
    and send/receive SMS and voice; store and retrieve vault credentials; manage
    agent identity; and configure webhooks for real-time events. Authenticate
    using a Bearer token or an API key passed via the X-API-Key header.
  contact:
    name: Anima Labs
    url: https://useanima.sh
    email: support@useanima.sh
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.useanima.sh/v1
    description: Production
security:
  - BearerAuth: []
  - ApiKeyAuth: []
paths:
  /extension/exchange:
    post:
      operationId: extension.exchangeToken
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                code:
                  type: string
                  minLength: 1
                  description: One-time exchange code from createToken
              required:
                - code
              description: Request body for exchanging a code for extension credentials
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: Extension auth token (API key) for the browser extension
                  signingSecret:
                    type: string
                    description: HMAC signing secret for WebSocket bridge messages
                  orgId:
                    type: string
                    description: Organization ID for channel subscription
                  expiresAt:
                    anyOf:
                      - type: string
                        format: date-time
                      - type: 'null'
                    description: ISO 8601 expiration time. Null for session-based.
                  requiresApproval:
                    type: boolean
                    description: >-
                      Whether the owner must approve this token in the extension
                      UI
                required:
                  - token
                  - signingSecret
                  - orgId
                  - expiresAt
                  - requiresApproval
                description: Extension credentials returned after code exchange
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT Bearer token obtained from authentication. Pass as: Authorization:
        Bearer <token>
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: 'API key for programmatic access. Pass as: X-API-Key: <your-key>'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.