# Issue TURN credentials Create temporary STUN/TURN ICE server credentials. ## Requirements A secret API key with `tokens:create`. Resources are restricted to the key's project and environment. ## Request body | Name | Type | Required / default | Description | | --- | --- | --- | --- | | roomId | string | Optional with sessionId | Room of the active session. | | sessionId | string | Optional with roomId | Active participant session. | ## Example Set `RELAYRTC_API_URL` to your API base including `/v1`, such as `http://localhost:8082/v1`. ```bash curl -X POST "$RELAYRTC_API_URL/turn/credentials" \ -H "Authorization: Bearer $RELAYRTC_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{"roomId":"room_example","sessionId":"session_example"}' ``` ## Response `201` with [TURN credentials](/reference/api/v1/schemas/turn-credentials). URLs, username, lifetime and password depend on the deployment. ```json { "expiresAt": "2026-01-01T12:10:00.000Z", "username": "issued-turn-username", "ttlSeconds": 600, "iceServers": [ { "urls": [ "stun:turn.your-domain.example:3478" ] }, { "urls": [ "turn:turn.your-domain.example:3478?transport=udp" ], "username": "issued-turn-username", "credential": "issued-turn-password", "credentialType": "password" } ] } ``` ## Notes Supply both IDs for session-bound credentials or send `{}` for environment-scoped credentials. A browser joining through the SDK receives initial TURN credentials from signaling. Keep the secret API key on the backend when renewing them. ## Errors Invalid fields return `400`. Invalid credentials return `401`; a missing scope returns `403`. A missing resource returns `404`. See [error responses](/reference/api/v1/errors).