Runs the admission rules against a candidate declaration and reports the verdict.
Persists nothing and contacts nothing — no row is written, no audit row is
emitted and the issuer is never reached over the network, so this is not an egress
surface and cannot be used to probe one.
It answers 200 with admitted: false for a descriptor the
rules refuse, rather than 4xx: a refusal is the ANSWER to the question that was
asked, and an operator filling in an onboarding form needs the reason next to the
field, not an error page.
The verdict reports the CANONICAL issuer the declaration would be stored under, which is frequently not the string that was typed. Seeing it before writing is the point: an operator who expected a trailing slash to survive finds out here rather than after the customer's tokens start being refused.
It is still a WRITE-plane surface in the sense that matters for the ROOT target — it is refused for the ROOT tenant so that the answer never describes a declaration that could not be written anyway.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||