> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vellaro.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Preview Token

> Mint a signed, short-lived LIVE-PREVIEW capability for a page's draft (F2).

The tenant comes from ``request.state.tenant_id`` (the staff JWT's signed
``tenant_id`` claim — NEVER client input), so a staff member can only ever
mint a token for their OWN tenant even behind the shared admin host.
``_load_page`` runs under RLS, so an id belonging to another tenant is 404,
not a mintable token. The token binds tenant_id + page_id + slug; the
storefront draft-preview endpoint re-checks all three. Publishes nothing,
mutates nothing.



## OpenAPI

````yaml https://api.vellaro.io/openapi.json post /api/v1/admin/cms/pages/{page_id}/preview-token
openapi: 3.1.0
info:
  title: Vellaro API
  description: Vellaro 2026 — E-commerce API
  version: 0.1.0
servers:
  - url: https://api.vellaro.io
    description: Produzione
security: []
tags: []
paths:
  /api/v1/admin/cms/pages/{page_id}/preview-token:
    post:
      tags:
        - admin:cms-pages
      summary: Create Preview Token
      description: >-
        Mint a signed, short-lived LIVE-PREVIEW capability for a page's draft
        (F2).


        The tenant comes from ``request.state.tenant_id`` (the staff JWT's
        signed

        ``tenant_id`` claim — NEVER client input), so a staff member can only
        ever

        mint a token for their OWN tenant even behind the shared admin host.

        ``_load_page`` runs under RLS, so an id belonging to another tenant is
        404,

        not a mintable token. The token binds tenant_id + page_id + slug; the

        storefront draft-preview endpoint re-checks all three. Publishes
        nothing,

        mutates nothing.
      operationId: create_preview_token_api_v1_admin_cms_pages__page_id__preview_token_post
      parameters:
        - name: page_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Page Id
        - name: locale
          in: query
          required: false
          schema:
            type: string
            default: it
            title: Locale
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_CmsPreviewTokenOut_'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - HTTPBearer: []
components:
  schemas:
    ApiResponse_CmsPreviewTokenOut_:
      properties:
        data:
          anyOf:
            - $ref: '#/components/schemas/CmsPreviewTokenOut'
            - type: 'null'
        meta:
          anyOf:
            - $ref: '#/components/schemas/PaginationMeta'
            - type: 'null'
        error:
          anyOf:
            - type: string
            - type: 'null'
          title: Error
        error_code:
          anyOf:
            - type: string
            - type: 'null'
          title: Error Code
      type: object
      title: ApiResponse[CmsPreviewTokenOut]
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    CmsPreviewTokenOut:
      properties:
        token:
          type: string
          title: Token
        preview_url:
          type: string
          title: Preview Url
        expires_at:
          type: string
          format: date-time
          title: Expires At
        expires_in_seconds:
          type: integer
          title: Expires In Seconds
      type: object
      required:
        - token
        - preview_url
        - expires_at
        - expires_in_seconds
      title: CmsPreviewTokenOut
      description: >-
        The signed live-preview capability (F2) handed to the admin composer.


        ``preview_url`` is the fully-qualified storefront route (built
        server-side

        from the tenant's own domain, so the admin needs no storefront-origin
        env)

        that renders the draft when loaded in the iframe. ``token`` is exposed

        separately so the composer can re-mint / cache-bust without a full URL
        parse.
    PaginationMeta:
      properties:
        page:
          type: integer
          title: Page
        page_size:
          type: integer
          title: Page Size
        total:
          type: integer
          title: Total
        total_pages:
          type: integer
          title: Total Pages
      type: object
      required:
        - page
        - page_size
        - total
        - total_pages
      title: PaginationMeta
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.