A valid request URL is required to generate request examples{
"gatewayId": "<string>",
"credential": "<string>",
"tunnelUrl": "<string>",
"releaseChannel": "<string>",
"siteId": "<string>"
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}Enroll a gateway computer
A new gateway computer trades an enrollment code, once, for its gateway id and tunnel credential. The installer calls it over HTTPS before the computer has any credential, so no Authorization is read: the code in the body is the credential. A gateway-bound code has 8 characters and lives 15 minutes; a legacy site-only code has 6 characters and lives 30 minutes. Both are used once and belong to one site. Both shapes are accepted during the rollout overlap.
A code that cannot be used is always answered the same way (410 ENROLL_CODE_INVALID, the same message), whether it is malformed, unknown, expired, revoked, locked or already used. The response body does not reveal whether a code exists; this is not a constant-time guarantee. ENROLL_CODE_EXPIRED is retired.
Failures are throttled before any database work, per api process: 10 a minute per client (an IPv4 address, or an IPv6 /64), and 60 a minute with a well-formed code across all clients. Once the global budget is spent, sources with recent successful enrollment or tunnel authentication share one extra 20-per-minute lane; their per-client limit still applies. Malformed codes spend only the per-client budget. Successful exchanges and 503 responses refund both reservations. A request carrying a real code with another field wrong counts against that code; after 5 the code is refused for good. At most 4 exchanges are in progress at once per machine; beyond that the answer is 503 with Retry-After: 1, not counted as a failure. Bodies over 8192 bytes are read as carrying no code.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"gatewayId": "<string>",
"credential": "<string>",
"tunnelUrl": "<string>",
"releaseChannel": "<string>",
"siteId": "<string>"
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}{
"error": {
"code": "ENROLL_CODE_INVALID",
"message": "<string>"
}
}Body
What the computer says about itself, and the code.
The enrollment code: 8 Crockford Base32 characters for a gateway-bound code, or 6 for a legacy site-only code during the overlap. Case, spaces and hyphens are forgiven, and O, I and L are read as 0, 1 and 1. Other lengths are refused.
The Ed25519 public key generated on the computer: 32 bytes, unpadded base64url (43 characters; one trailing = is forgiven). A non-canonical point encoding or one of the eight points of small order is refused with ENROLL_REQUEST_INVALID. The computer keeps the private key in its secret store and signs its continuity proofs with it; the platform keeps only this public key and verifies the proofs against it.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Response
Enrolled. Cache-Control: no-store.
The gateway's id: the pre-created target for a gateway-bound code, or a new id for a legacy site-only code.
The gateway's tunnel credential, in this response only. It serves no device until one is bound to the gateway. Keep it in the platform secret store, never in shell history, environment files or service units.
The WebSocket URL the gateway connects to with its credential.
The gateway's release channel: production on the declared production deployment; otherwise the legacy default stable.
The site the code was issued for.