Skip to content

Identity: leaf

View as Markdown

Install the chain the wallet issued: the identity becomes, or renews as, 2.0

Section titled “Install the chain the wallet issued: the identity becomes, or renews as, 2.0”

POST /v1/identities/{slug}/leaf · operation installLeaf

Requires the batondeck:identities:manage permission (action cert:install).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. Not reachable with an API key — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

Parameters

Name In Type Required Notes
slug path string yes

Request body (application/json)

Field Type Required Notes
chain array of string yes
credential_id string \ null
backup_verified boolean \ null
Request schema
{
"type": "object",
"properties": {
"chain": {
"minItems": 2,
"maxItems": 2,
"type": "array",
"items": {
"type": "string",
"minLength": 1
}
},
"credential_id": {
"anyOf": [
{
"type": "string",
"minLength": 1,
"maxLength": 512
},
{
"type": "null"
}
]
},
"backup_verified": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
]
}
},
"required": [
"chain"
],
"additionalProperties": false
}

Responses

Status Meaning
201 Install the chain the wallet issued: the identity becomes, or renews as, 2.0
400 The arguments did not validate.
401 No portal session, and no live API key.
403 The policy refused, or the request was cross-site.
404 No such resource, or none this session may see.
201 response schema
{
"type": "object",
"properties": {
"root_fingerprint": {
"type": "string"
},
"kid": {
"type": "string"
},
"endpoint": {
"type": "string"
},
"not_before": {
"type": "string"
},
"not_after": {
"type": "string"
},
"purpose": {
"type": "string"
},
"first": {
"type": "boolean"
},
"superseded_kid": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
]
}
},
"required": [
"root_fingerprint",
"kid",
"endpoint",
"not_before",
"not_after",
"purpose",
"first",
"superseded_kid"
],
"additionalProperties": false
}
Terminal window
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/leaf' \
-H "Authorization: Bearer $BATONDECK_API_KEY" \
-H 'content-type: application/json' \
-d @body.json