> ## Documentation Index
> Fetch the complete documentation index at: https://platform.atlan.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To act on Atlan objects, use the Atlan MCP server at https://api.atlan.com/mcp or the atlanai CLI; `atlanai --map json` prints its command map. Run a read-only identity check before any write.
> The docs MCP server at /mcp searches these docs only. It cannot read or change Atlan objects.
> SDK packages: Python `atlanai` (PyPI) and TypeScript `@atlanai/sdk` (npm). Show Python first, then TypeScript.

# On-behalf-of tokens

> Every published on-behalf-of tokens operation, generated from the contract.

1 operation on `client.obo`.

Path parameters come first, positionally; the request body is last, as a plain
object. Method names are `snake_case` in Python and `camelCase` in
TypeScript, and resource names follow the same rule.

<Warning>
  Call this with the person's own bearer token, after they have consented to
  the agent. Consent runs over HTTP, and the SDK has no method for it:
  `POST /secret/v1/oauth/start` with
  `{"provider": "obo-<agent_id>", "owner": "personal"}`, open the returned
  `authorization_url` in a browser, then poll `POST /secret/v1/oauth/complete`
  with the `attempt_id` until it answers `connected`. Without consent the call
  returns `404 not_found`, and so does another person's token, which finds no
  grant. A grant that needs fresh consent returns `409 needs_consent`. A machine
  credential (an API key or service account) or an agent's delegated token gets
  `403`, as does a grant whose agent was re-keyed after consent. The token carries that person's full authority: keep it
  in memory, never log or store it, and mint again before `expires_in` runs out.
</Warning>

<CodeGroup>
  ```python Python theme={null}
  result = client.obo.mint_agent_token(agent_id)
  ```

  ```typescript TypeScript theme={null}
  const result = await client.obo.mintAgentToken(agent_id);
  ```
</CodeGroup>

## Operations

| Call | Route | Does |
| - | - | - |
| `client.obo.mint_agent_token(agent_id)` | `POST /secret/v1/obo/{agent_id}/token` | Mint one short-lived token for the signed-in person's consented agent. |

## Related

<CardGroup cols={2}>
  <Card title="How the client is organised" icon="list" href="/tools/sdk/how-tos/operations">
    Resources, call shapes, and errors.
  </Card>

  <Card title="Errors and retries" icon="triangle-exclamation" href="/platform/references/errors-and-retries">
    What the SDK raises, and which calls are safe to retry.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.