Skip to content

Identity: csr

View as Markdown

Mint a key and a certificate signing request for the wallet to sign (SPEC §9)

Section titled “Mint a key and a certificate signing request for the wallet to sign (SPEC §9)”

POST /v1/identities/{slug}/csr · operation issueCsr

Requires the batondeck:identities:manage permission (action cert:csr).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. Not reachable with an API key — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

Parameters

Name In Type Required Notes
slug path string yes

Request body (application/json)

Field Type Required Notes
purpose “signup” \ “renew” \ “move”
endpoint string ≥ 1 chars, ≤ 512 chars
Request schema
{
"type": "object",
"properties": {
"purpose": {
"type": "string",
"enum": [
"signup",
"renew",
"move"
]
},
"endpoint": {
"type": "string",
"minLength": 1,
"maxLength": 512
}
},
"required": [
"purpose"
],
"additionalProperties": false
}

Responses

Status Meaning
201 Mint a key and a certificate signing request for the wallet to sign (SPEC §9)
400 The arguments did not validate.
401 No portal session, and no live API key.
403 The policy refused, or the request was cross-site.
404 No such resource, or none this session may see.
201 response schema
{
"type": "object",
"properties": {
"csr": {
"type": "string"
},
"endpoint": {
"type": "string"
},
"purpose": {
"type": "string"
},
"suggested_not_after": {
"type": "string"
},
"previous_not_before": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
]
},
"key_fingerprint": {
"type": "string"
}
},
"required": [
"csr",
"endpoint",
"purpose",
"suggested_not_after",
"previous_not_before",
"key_fingerprint"
],
"additionalProperties": false
}
Terminal window
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/csr' \
-H "Authorization: Bearer $BATONDECK_API_KEY" \
-H 'content-type: application/json' \
-d @body.json