Identity: leaf
Install the chain the wallet issued: the identity becomes, or renews as, 2.0
Section titled “Install the chain the wallet issued: the identity becomes, or renews as, 2.0”POST /v1/identities/{slug}/leaf · operation installLeaf
Requires the batondeck:identities:manage permission (action cert:install).
Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. Not reachable with an API key — a key has no session and so can never step up.
Refused while the workspace is suspended or on deletion hold.
Parameters
| Name | In | Type | Required | Notes |
|---|---|---|---|---|
slug |
path | string | yes |
Request body (application/json)
| Field | Type | Required | Notes |
|---|---|---|---|
chain |
array of string | yes | |
credential_id |
string \ | null | |
backup_verified |
boolean \ | null |
Request schema
{ "type": "object", "properties": { "chain": { "minItems": 2, "maxItems": 2, "type": "array", "items": { "type": "string", "minLength": 1 } }, "credential_id": { "anyOf": [ { "type": "string", "minLength": 1, "maxLength": 512 }, { "type": "null" } ] }, "backup_verified": { "anyOf": [ { "type": "boolean" }, { "type": "null" } ] } }, "required": [ "chain" ], "additionalProperties": false}Responses
| Status | Meaning |
|---|---|
| 201 | Install the chain the wallet issued: the identity becomes, or renews as, 2.0 |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |
201 response schema
{ "type": "object", "properties": { "root_fingerprint": { "type": "string" }, "kid": { "type": "string" }, "endpoint": { "type": "string" }, "not_before": { "type": "string" }, "not_after": { "type": "string" }, "purpose": { "type": "string" }, "first": { "type": "boolean" }, "superseded_kid": { "anyOf": [ { "type": "string" }, { "type": "null" } ] } }, "required": [ "root_fingerprint", "kid", "endpoint", "not_before", "not_after", "purpose", "first", "superseded_kid" ], "additionalProperties": false}curl -X POST 'https://api.batondeck.com/v1/identities/:slug/leaf' \ -H "Authorization: Bearer $BATONDECK_API_KEY" \ -H 'content-type: application/json' \ -d @body.json