/ Docs
APIDevice enrollment

Exchange Device Assertion

Exchange a signed device assertion for a short-lived runtime session. The device registry is read live on every call and a device that is not active is refused here, before its signature is even examined. There is no cache, no TTL and no memoised lookup between that row and this decision, and there must never be one: it is the only reason a credential that never expires can still be revoked.

POST
/v1/public/device-assertion/exchange

Authorization

BearerAuth
AuthorizationBearer <token>

Botyard API key — see /docs/authentication.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

A device presenting proof that it holds its registered private key.

The assertion is the entire request. There is no device id, bot id or anything else alongside it, deliberately: every identity claim is inside the signed blob, so nothing here can assert an identity the signature does not cover.

Response Body

application/json

curl -X POST "https://example.com/v1/public/device-assertion/exchange" \  -H "Content-Type: application/json" \  -d '{    "assertion": "string"  }'
{
  "session_token": "string",
  "session_id": "string",
  "runtime_id": "string",
  "bot_id": "string",
  "device_id": "string",
  "gateway_url": "string",
  "spiffe_id": "string",
  "issued_at": "2019-08-24T14:15:22Z",
  "expires_at": "2019-08-24T14:15:22Z",
  "trust_tier": "user_attached",
  "effect_coverage": "mediated"
}
{
  "type": "string",
  "title": "string",
  "status": 0,
  "detail": "string",
  "instance": "string",
  "error_code": "string",
  "errors": [
    {
      "pointer": "string",
      "detail": "string",
      "type": "string"
    }
  ],
  "trace_id": "string"
}