On this page
createTokenAccount
mutation · in the family Token account
What it does
Create a new your group’s kernel wallet — the prepaid balance that pays for platform usage at your organization.
Open the caller's group's ONE TokenAccount. ⚠ Opening the wallet ARMS the metering (ruling — wallet existence IS the arm; the rater leg debits it). Requires the unrestricted capability. Template class A16_BILLING (hand-derived v23).
Who may call it
Capability area: Billing and the wallet — Your platform bill, token purchases and the usage and cost reads.
- Owner
- Manager
- Associate Manager
- An API key whose scope allows
api:createTokenAccount
Arguments
| Name | Type | Required | Notes |
|---|---|---|---|
input | NewTokenAccountInput NewTokenAccountInput! | yes | No further notes. |
Returns
TokenAccount TokenAccount! — A TokenAccount — **the ONE-per-GROUP token wallet / platform billing unit** (AT/stack billing of MERCHANTS; 1 org or 100 orgs share ONE pool — is the billing aggregation point; per-org figures are consumption ATTRIBUTION, reporting-only). The wallet is a GROUP-scoped SINGLETON enforced by the tokenAccountSingleton UNIQ marker minted IN the create txn. **Wallet existence IS the metering arm** (ruling): no wallet ⇒ the group is unbilled (the DVLP posture); opening one arms the rater (the slice-4 leg). balance = Σ TokenEntry amounts EXACTLY, cached in the SAME transaction as every ledger append — SIGNED (ruling: the ledger never lies; a transient sub-zero overshoot is honest state; exhaustion balance ≤ 0 fires the system:token_exhaustion CASCADE-suspend of member orgs, reload ≤0→>0 fires system:token_reload unsuspend-to-ACTIVE). The auto-top-off block is CONFIG this slice (the FIRING engine + stored-method custody = the rater leg, deferral 5); its budget cap is a LAZY month-keyed counter (ruling — rolls by key comparison, no scheduled reset). FSM: active(i) ⇄ inactive (paused — purchases/grants refuse REF_STATE; the rater still debits: usage happened) → doomed (gate-protected; the inbound-ref set is EMPTY by design — entries and purchases are FAMILY [the GiftRegistry vacuous-gate class]). Platform billing is USD-only. NOT searchable (platform-internal — never merchant search content). Template class A16_BILLING (platform billing ≠ floor work — owner/manager/assoc_mgr; hand-derived v23).
Example request
mutation ExampleCreateTokenAccount($input: NewTokenAccountInput!) {
createTokenAccount(input: $input) {
id
sysId
type
caption
status
parentId
rootId
createdAt
updatedAt
revisionNum
revision
balance
lowBalanceThreshold
dailyBurnThresholdKernels
autoTopOffMonth
autoTopOffSpentUsdCents
autoTopOffDay
autoTopOffSpentDayUsdCents
autoTopOffPendingMethod
autoTopOffPrimaryFailedDay
autoTopOffBackupFailedDay
burn7dKernels
runwayDays
microTokenCarry
lowBalanceSince
autoTopOffPendingPurchaseId
topOffCappedSince
baseFeePaidMonth
includedMonth
includedGranted
includedRemaining
affiliateCreditCents
frozenKernels
storageSnapshotDay
currency
}
}
Variables:
{
"input": {
"caption": "Blue jeans"
}
}
Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.
Example response
{
"data": {
"createTokenAccount": {
"id": "01900000-0000-7000-8000-37386ae00000",
"sysId": "TA-EXMP-0000-000F",
"type": "TokenAccount",
"caption": "Blue jeans",
"status": "active",
"parentId": "01900000-0000-7000-8000-065235280000",
"rootId": "01900000-0000-7000-8000-a093dd800000",
"createdAt": "2027-01-31T00:00:00.000Z",
"updatedAt": "2027-01-31T00:00:00.000Z",
"revisionNum": 1,
"revision": "01900000-0000-7000-8000-b7960e180000",
"balance": 1,
"lowBalanceThreshold": 1,
"dailyBurnThresholdKernels": 1,
"autoTopOffMonth": "<auto top off month>",
"autoTopOffSpentUsdCents": 1,
"autoTopOffDay": "2027-01-31",
"autoTopOffSpentDayUsdCents": 1,
"autoTopOffPendingMethod": "<auto top off pending method>",
"autoTopOffPrimaryFailedDay": "2027-01-31",
"autoTopOffBackupFailedDay": "2027-01-31",
"burn7dKernels": 1,
"runwayDays": 1.5,
"microTokenCarry": 1,
"lowBalanceSince": "<low balance since>",
"autoTopOffPendingPurchaseId": "01900000-0000-7000-8000-80a20c5b0000",
"topOffCappedSince": "<top off capped since>",
"baseFeePaidMonth": "<base fee paid month>",
"includedMonth": "<included month>",
"includedGranted": 1,
"includedRemaining": 1,
"affiliateCreditCents": 1,
"frozenKernels": 1,
"storageSnapshotDay": "2027-01-31",
"currency": "USD"
}
},
"extensions": {
"at": {
"callId": "01EXAMPLE-CALL-ID",
"version": {
"requested": {
"name": "genesis",
"number": 0
},
"serviced": {
"name": "genesis",
"number": 0
}
}
}
}
}
Errors this call can answer
VALIDATION/INVALID— Something in the request is not valid. (VALIDATION)AUTHN/REQUIRED— Sign in to do this. (AUTHN)AUTHZ/FORBIDDEN— Your role does not allow this action. (AUTHZ)RATE_LIMIT/THROTTLED— Too many requests in a short time. (RATE_LIMIT)CONFLICT/*— The record’s state, or a change made in the meantime, does not allow this; the codes are on the CONFLICT page. (CONFLICT)VALIDATION/VERSION_REQUIRED— The request did not say which app version it came from. (VALIDATION)
Dry run
Add dryRun: true to the request envelope (extensions.at) to rehearse this call: every check runs, the write is rehearsed against the current records and nothing is stored; the answer is the refusal a real call would give, or the record it would create. Every response to a rehearsal carries dryRun: true, so a rehearsed record is never mistaken for a saved one.