Exchange Device Assertion
Exchange a signed device assertion for a short-lived runtime session. The device registry is read live on every call and a device that is not active is refused here, before its signature is even examined. There is no cache, no TTL and no memoised lookup between that row and this decision, and there must never be one: it is the only reason a credential that never expires can still be revoked.
Authorization
BearerAuth Botyard API key — see /docs/authentication.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
A device presenting proof that it holds its registered private key.
The assertion is the entire request. There is no device id, bot id or anything else alongside it, deliberately: every identity claim is inside the signed blob, so nothing here can assert an identity the signature does not cover.
Response Body
application/json
curl -X POST "https://example.com/v1/public/device-assertion/exchange" \ -H "Content-Type: application/json" \ -d '{ "assertion": "string" }'{
"session_token": "string",
"session_id": "string",
"runtime_id": "string",
"bot_id": "string",
"device_id": "string",
"gateway_url": "string",
"spiffe_id": "string",
"issued_at": "2019-08-24T14:15:22Z",
"expires_at": "2019-08-24T14:15:22Z",
"trust_tier": "user_attached",
"effect_coverage": "mediated"
}{
"type": "string",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"error_code": "string",
"errors": [
{
"pointer": "string",
"detail": "string",
"type": "string"
}
],
"trace_id": "string"
}Set Oauth Tokens
Manually set OAuth tokens for a credential obtained from the Codex CLI. Use this when tokens were obtained via ``codex auth login`` rather than the browser popup flow. Tokens are stored with the same age-encryption as the standard OAuth callback path.
Exchange Pod Svid
Exchange a scheduled pod's JWT-SVID for a short-lived runtime session. The pod twin of :func:`exchange_device_assertion`: no enrollment token, no device key, no custody row. Attestation is the SVID itself, verified against the SPIRE OIDC discovery JWKS; the entry that lets SPIRE mint it is the scope control. Each SVID buys exactly one session (replay loses on the session row's unique index), so a pod fetches fresh per exchange and entry deletion stops new sessions within one SVID lifetime.