Skip to content

Issue an enrollment token

POST
/nodes/{nodeId}/enrollment-token
curl --request POST \
--url https://example.com/api/v1/nodes/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/enrollment-token \
--cookie __Host-shardkeep_session=<__Host-shardkeep_session>

Needs nodes.manage, and the Node must still be awaiting enrollment (node_enrolled otherwise). Give the token to the Agent on its first start (SHARDKEEP_ENROLL_TOKEN). It is valid for one hour and works once; issuing another replaces it. If it expires unused, the Node keeps waiting: issue a fresh token.

nodeId
required
string format: uuid

Token issued. Shown only once.

Media typeapplication/json
object
token
required

<id>.<secret>.<ca-pin>. The pin lets the Agent verify the Controller on first contact. Treat the whole token as a secret.

string
expiresAt
required
string format: date-time
Examplegenerated
{
"token": "example",
"expiresAt": "2026-04-15T12:00:00Z"
}

Not signed in, or the credentials are invalid.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Signed in, but not allowed.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Not found, or not visible to you.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Clashes with existing data or state.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}