Skip to main content
POST
Sign a daemon request with the caller's identity (deprecated alias)

Authorizations

Authorization
string
header
required

API key as bearer token in Authorization header

Path Parameters

internId
string
required

ID of an intern visible to the authenticated API key.

Minimum string length: 1
Example:

"7c9e6679-7425-40de-944b-e07fc1f90ae7"

Body

application/json
bodySha256
string
required

Lower-case hex SHA-256 of the exact bytes the CLI will send as the daemon request body.

Pattern: ^[0-9a-f]{64}$
Example:

"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"

Response

Signature headers for the digest.

Headers the CLI copies onto the daemon request so the sidecar can verify who is asking.

x-ori-invoke-signature
string
required

Base64 Ed25519 signature over the intern id, timestamp, user and body digest.

x-ori-invoke-timestamp
string
required

Unix seconds at signing; the daemon refuses proofs older than its window.

x-ori-invoke-user
string
required

The verified OAuth subject the proof names. Never taken from the request.