Redeem a sensor bootstrap token
const url = 'https://api.nextpki.com/v1/sensors/bootstrap';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"token":"example","machine_id":"example","csr":"example","os":"linux","arch":"amd64","version":"0.1.0"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.nextpki.com/v1/sensors/bootstrap \ --header 'Content-Type: application/json' \ --data '{ "token": "example", "machine_id": "example", "csr": "example", "os": "linux", "arch": "amd64", "version": "0.1.0" }'Exchanges a single-use bootstrap token for a sensor identity: a signed client certificate, the CA chain and the SPIFFE ID the sensor will present on every later call.
This is the one endpoint that takes no Authorization header. A
sensor that is registering has no API token yet; the bootstrap token in
the body is the credential. It is worth exactly one successful call - a
second attempt is refused with token_already_used.
Rate limit: 1 request per second per source address, burst 5.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Single-use bootstrap token, of the form npbst.
Stable identifier of the machine (hostname, OS UUID). Must match the token’s hint if one was set.
PKCS#10 certificate signing request, either PEM or base64-encoded DER.
Example
linuxExample
amd64Sensor version
Example
0.1.0Responses
Section titled “Responses”Registered - the certificate is valid for 90 days
object
Signed client certificate
Issuing CA
Where the sensor reports its findings
Example
{ "spiffe_id": "spiffe://nextpki.com/tenant/<uuid>/sensor/<machine_id>"}Malformed body, undecodable CSR, or a machine_id that does not
match the hint the token was issued for. The token is not
consumed in this case.
object
Error class - what a program branches on.
The specific cause - what a human reads in a terminal.
Example
{ "error": "invalid_request", "reason": "token_unknown"}Token refused. reason names which case it is - token_unknown,
token_expired or token_already_used - so an operator at a
terminal can tell them apart without asking us.
object
Error class - what a program branches on.
The specific cause - what a human reads in a terminal.
Example
{ "error": "invalid_request", "reason": "token_unknown"}Too many attempts from this address
object
Error class - what a program branches on.
The specific cause - what a human reads in a terminal.
Example
{ "error": "invalid_request", "reason": "token_unknown"}