Skip to main content
POST
Error

Body

application/json

What the computer says about itself, and the code.

code
string
required

The enrollment code: 8 Crockford Base32 characters for a gateway-bound code, or 6 for a legacy site-only code during the overlap. Case, spaces and hyphens are forgiven, and O, I and L are read as 0, 1 and 1. Other lengths are refused.

publicKey
string
required

The Ed25519 public key generated on the computer: 32 bytes, unpadded base64url (43 characters; one trailing = is forgiven). A non-canonical point encoding or one of the eight points of small order is refused with ENROLL_REQUEST_INVALID. The computer keeps the private key in its secret store and signs its continuity proofs with it; the platform keeps only this public key and verifies the proofs against it.

host
object
required
edge
object
required

Response

Enrolled. Cache-Control: no-store.

gatewayId
string
required

The gateway's id: the pre-created target for a gateway-bound code, or a new id for a legacy site-only code.

credential
string
required

The gateway's tunnel credential, in this response only. It serves no device until one is bound to the gateway. Keep it in the platform secret store, never in shell history, environment files or service units.

tunnelUrl
string
required

The WebSocket URL the gateway connects to with its credential.

releaseChannel
string
required

The gateway's release channel: production on the declared production deployment; otherwise the legacy default stable.

siteId
string
required

The site the code was issued for.