# Identity: wallet request

> Mint a CSR and open a single-use request for the wallet page to sign (onboarding/wallet design §1a); What the wallet did with a request: still open, the chain it issued, or why it did not

## Mint a CSR and open a single-use request for the wallet page to sign (onboarding/wallet design §1a)

`POST /v1/identities/{slug}/wallet-request` · operation `openWalletRequest`

Requires the `batondeck:identities:manage` permission (action `cert:csr`).

Requires a step-up: MFA enrolled and re-authenticated within 15 minutes. **Not reachable with an API key** — a key has no session and so can never step up.

Refused while the workspace is suspended or on deletion hold.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |

**Request body** (`application/json`)

| Field | Type | Required | Notes |
|---|---|---|---|
| `purpose` | "signup" \\| "renew" \\| "move" | yes |  |
| `endpoint` | string |  | ≥ 1 chars, ≤ 512 chars |

<details>
<summary>Request schema</summary>

```json
{
  "type": "object",
  "properties": {
    "purpose": {
      "type": "string",
      "enum": [
        "signup",
        "renew",
        "move"
      ]
    },
    "endpoint": {
      "type": "string",
      "minLength": 1,
      "maxLength": 512
    }
  },
  "required": [
    "purpose"
  ],
  "additionalProperties": false
}
```

</details>

**Responses**

| Status | Meaning |
|---|---|
| 201 | Mint a CSR and open a single-use request for the wallet page to sign (onboarding/wallet design §1a) |
| 400 | The arguments did not validate. |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>201 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string"
    },
    "url": {
      "type": "string"
    },
    "endpoint": {
      "type": "string"
    },
    "purpose": {
      "type": "string"
    },
    "expires_at": {
      "type": "number"
    }
  },
  "required": [
    "code",
    "url",
    "endpoint",
    "purpose",
    "expires_at"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/wallet-request' \
  -H "Authorization: Bearer $BATONDECK_API_KEY" \
  -H 'content-type: application/json' \
  -d @body.json
```


## What the wallet did with a request: still open, the chain it issued, or why it did not

`GET /v1/identities/{slug}/wallet-request/{code}` · operation `readWalletRequest`

Requires the `batondeck:identities:read` permission (action `cert:read`).

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |
| `code` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | What the wallet did with a request: still open, the chain it issued, or why it did not |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "enum": [
        "open",
        "answered",
        "cancelled",
        "failed",
        "expired"
      ]
    },
    "chain": {
      "anyOf": [
        {
          "minItems": 2,
          "maxItems": 2,
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        {
          "type": "null"
        }
      ]
    },
    "root_fingerprint": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "credential_id": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ]
    },
    "backup_verified": {
      "type": "boolean"
    },
    "why": {
      "type": "string"
    }
  },
  "required": [
    "state",
    "chain",
    "root_fingerprint",
    "credential_id",
    "backup_verified",
    "why"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/identities/:slug/wallet-request/:code' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```
