Skip to content
POST
/v1/bootstrap

Create Cantora's Organization, its provisioning ServicePrincipal, and its credential

Perform the one-time platform bootstrap and return the provisioning API key exactly once. This operation is for Cantora operators, not customer credentials.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

This operation has no path or query parameters.

Responses

201PlatformBootstrapped
401Unauthorized
application/json
403Forbidden
application/json

Reusable schemas

PlatformBootstrappedEncoded

object
  • unknown properties allowed false
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
organizationNamerequired
stringThe customer-facing Organization name.
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
grantIdrequired
stringThe Grant identifier.
  • maximum length 64
  • pattern ^grant_[\s\S]+$
apiKeyIdrequired
stringThe identifier of the issued API key.
  • maximum length 64
  • pattern ^apikey_[\s\S]+$
apiKeyrequired
stringThe provisioning credential, returned exactly once and never recoverable from Cantora
expiresAtrequired
stringWhen the resource expires, in UTC, or null when it does not expire.
  • format date-time

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.