Admit a tenant's issuer into its trust set (platform)

Puts the declaration into the tenant's effective trust set. Until this runs, a token
from that issuer is refused however correctly the declaration describes it — which
is what makes an abandoned half-finished onboarding harmless.

This is the verb that actually widens what the deployment will accept for this customer, so it is the one an operator should be able to point at in an audit. The row is filed under the customer.

Idempotent: enabling an already-enabled issuer returns the same 200 and the same body. Trust is a state, not a counter.

Not entitlement-gated. The operator is the party that sells the edition, so

refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json