Skip to main content
POST
Issue a credential for the authenticated integrator

Authorizations

X-Pubkey, X-Timestamp, X-Signature
string
header
required

Headers

X-Pubkey
string
required

Integrator's ECDSA public key (P-256 curve, compressed SEC1 format). Example: 0x038fedef7c12f93bbf342ad8943b7a825a3b41f61c9dc118b2c718efebabbf62fd

X-Timestamp
string
required

Unix timestamp in seconds (UTC). Must be within tolerance window (1 minute) to prevent replay attacks. Example: 1760375826

X-Signature
string
required

ECDSA signature (DER-encoded, hex with 0x prefix). Signs the message: {timestamp}{METHOD}{path_and_query}{json_body}. Example: 0x3045022100...

Body

application/json
accessScope
enum<string>
Available options:
read_write,
read_only
Example:

"read_write"

label
string | null

Optional label for the new credential.

Response

Credential issued successfully

pubkey
string
required

Public key identifying the newly issued credential.

privateKey
string
required

Private key for the newly issued credential. Returned only at creation time.

integratorId
string<uuid>
required

A UUID string

Example:

"550e8400-e29b-41d4-a716-446655440000"

accessScope
enum<string>
required
Available options:
read_write,
read_only
Example:

"read_write"

active
boolean
required

Whether the credential is active immediately after creation.

label
string | null

Label of the credential.