Redeem an enrollment token for an agent key
POST /v1/enroll
Validates the token (not revoked/expired/exhausted) and creates a permissioned agent key bound to an agent. Idempotent on agent_handle. Also accepts a client-supplied idempotency key (Idempotency-Key header or client_id body field) to replay the original response on retry.
Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters ”Optional client-supplied key making a CREATE exactly-once. A retry with the same key returns the ORIGINAL response (same status + body) instead of creating a duplicate; the same key with a different request body returns 409. The body field client_id is honored as an alias when this header is absent. The key is scoped per tenant (and per agent on the agent plane), so keys never collide across callers.
Request Body required
Section titled “Request Body required ”object
Example
pk_enroll_<id>_<secret>Idempotency key for the agent identity.
Optional idempotency key (alias for the Idempotency-Key header). A retry with the same key replays the original enrollment response.
Responses
Section titled “ Responses ”Agent key created (shown once).
object
Pk_agent_…, shown once.
The fixed org the new key is bound to (the token’s resolved org).
The fixed project the new key is bound to (the token’s resolved project); the agent cannot change it.
Invalid request.
The canonical error envelope. error is a stable machine code.
object
Stable error code (e.g. unauthorized, forbidden, not_found, invalid, quota_exceeded, rate_limited).
Example
forbiddenHuman-readable detail (never leaks internals).
Example
missing required scopeMissing or invalid credential.
The canonical error envelope. error is a stable machine code.
object
Stable error code (e.g. unauthorized, forbidden, not_found, invalid, quota_exceeded, rate_limited).
Example
forbiddenHuman-readable detail (never leaks internals).
Example
missing required scopeAuthenticated but lacking the required scope, or out of quota.
The canonical error envelope. error is a stable machine code.
object
Stable error code (e.g. unauthorized, forbidden, not_found, invalid, quota_exceeded, rate_limited).
Example
forbiddenHuman-readable detail (never leaks internals).
Example
missing required scopeThe supplied idempotency key was already used with a different request body (error = idempotency_conflict).
The canonical error envelope. error is a stable machine code.
object
Stable error code (e.g. unauthorized, forbidden, not_found, invalid, quota_exceeded, rate_limited).
Example
forbiddenHuman-readable detail (never leaks internals).
Example
missing required scope