Puts the declaration into the tenant's effective trust set. Until this runs, a token
from that issuer is refused however correctly the declaration describes it — which
is what makes an abandoned half-finished onboarding harmless.
This is the verb that actually widens what the deployment will accept for this customer, so it is the one an operator should be able to point at in an audit. The row is filed under the customer.
Idempotent: enabling an already-enabled issuer returns the same 200 and the same body. Trust is a state, not a counter.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||