Identity: csr
Mint a key and a certificate signing request for the wallet to sign (SPEC §9)
Section titled “Mint a key and a certificate signing request for the wallet to sign (SPEC §9)”POST /v1/identities/{slug}/csr · operation issueCsr
Requires the batondeck:identities:manage permission (action cert:csr).
Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. Not reachable with an API key — a key has no session and so can never step up.
Refused while the workspace is suspended or on deletion hold.
Parameters
| Name | In | Type | Required | Notes |
|---|---|---|---|---|
slug |
path | string | yes |
Request body (application/json)
| Field | Type | Required | Notes |
|---|---|---|---|
purpose |
“signup” \ | “renew” \ | “move” |
endpoint |
string | ≥ 1 chars, ≤ 512 chars |
Request schema
{ "type": "object", "properties": { "purpose": { "type": "string", "enum": [ "signup", "renew", "move" ] }, "endpoint": { "type": "string", "minLength": 1, "maxLength": 512 } }, "required": [ "purpose" ], "additionalProperties": false}Responses
| Status | Meaning |
|---|---|
| 201 | Mint a key and a certificate signing request for the wallet to sign (SPEC §9) |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |
201 response schema
{ "type": "object", "properties": { "csr": { "type": "string" }, "endpoint": { "type": "string" }, "purpose": { "type": "string" }, "suggested_not_after": { "type": "string" }, "previous_not_before": { "anyOf": [ { "type": "string" }, { "type": "null" } ] }, "key_fingerprint": { "type": "string" } }, "required": [ "csr", "endpoint", "purpose", "suggested_not_after", "previous_not_before", "key_fingerprint" ], "additionalProperties": false}curl -X POST 'https://api.batondeck.com/v1/identities/:slug/csr' \ -H "Authorization: Bearer $BATONDECK_API_KEY" \ -H 'content-type: application/json' \ -d @body.json