{
  "info": {
    "name": "ePahichan API 1.0.0-draft",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json",
    "description": "Generated from the published contract. Set base_url and access_token; calls also need your client certificate (mutual TLS), configured in Postman's certificate settings."
  },
  "variable": [
    {
      "key": "base_url",
      "value": "https://api.sandbox.example"
    },
    {
      "key": "access_token",
      "value": ""
    }
  ],
  "item": [
    {
      "name": "Applications",
      "item": [
        {
          "name": "Poll a long-running operation",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/operations/{{operation_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "operations",
                "{{operation_id}}"
              ]
            },
            "description": "getOperation\n\nReturns the current state of work that could not complete within the\nrequest that started it."
          }
        },
        {
          "name": "List webhook delivery attempts",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/webhook-deliveries",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "webhook-deliveries"
              ]
            },
            "description": "listWebhookDeliveryAttempts\n\nEvery attempt made to deliver an event to one of the calling\norganization's endpoints, with the response, the timings and the\noutcome."
          }
        },
        {
          "name": "Inspect one webhook delivery attempt",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/webhook-deliveries/{{delivery_attempt_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "webhook-deliveries",
                "{{delivery_attempt_id}}"
              ]
            },
            "description": "getWebhookDeliveryAttempt\n\nOne delivery attempt in full: the event envelope exactly as it was\nsigned and sent, the signing key identifier, the response status and\ntruncated body, the timings, and the next scheduled attempt where one\nis pending."
          }
        },
        {
          "name": "Send one recorded event again",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/webhook-deliveries/{{delivery_attempt_id}}/redeliver",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "webhook-deliveries",
                "{{delivery_attempt_id}}",
                "redeliver"
              ]
            },
            "description": "redeliverWebhookEvent\n\nQueue the event carried by this attempt for delivery again. Use it\nafter fixing a broken consumer, or after replacing an endpoint that had\npermanently failed.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Send a batch of recorded events again",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/webhook-redeliveries",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "webhook-redeliveries"
              ]
            },
            "description": "createWebhookRedelivery\n\nQueue many recorded events for delivery again in one request. This is\nthe recovery path after an endpoint outage, where an organization has\nhours of `abandoned` attempts and calling the single-event operation in\na loop would be both slow and rate-limited.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List applications",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications"
              ]
            },
            "description": "listApplications\n\nReturns the applications registered under the organizations visible to\nthe caller, newest first by default."
          }
        },
        {
          "name": "Register an application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications"
              ]
            },
            "description": "registerApplication\n\nRegisters a new workload under the caller's organization, in the\ncaller's own environment. The environment is not a parameter: an\napplication may only register another application in the environment it\nitself occupies, which is what keeps sandbox configuration from reaching\nproduction by mistake.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one application",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}"
              ]
            },
            "description": "getApplication\n\nReturns the application: environment, state, contacts, redirect URIs,\nrate limits and its **effective capabilities**."
          }
        },
        {
          "name": "Update an application's configuration",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}"
              ]
            },
            "description": "updateApplication\n\nUpdates the mutable configuration of an application: display name,\ndescription, security and operational contacts, and redirect URIs.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Disable an application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/disablement",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "disablement"
              ]
            },
            "description": "disableApplication\n\nDisables one application immediately. Its access tokens stop being\naccepted, its workload certificates stop authenticating, and every\noperation it attempts fails closed with a distinguishable error rather\nthan degrading silently.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Reinstate a disabled application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/reinstatement",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "reinstatement"
              ]
            },
            "description": "reinstateApplication\n\nReturns a disabled application to service. Reinstatement is deliberately\nnot symmetric with disablement: disabling is fast and available to any\nadministrator under pressure, while reinstating requires a stated reason\nand restores nothing that was revoked.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List an application's capability grants",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/capability-grants",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "capability-grants"
              ]
            },
            "description": "listApplicationCapabilityGrants\n\nReturns the capabilities granted directly to this application, each with\nits effective period, reason, granting actor, and whether it is\ncurrently effective."
          }
        },
        {
          "name": "Grant a capability to an application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/capability-grants",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "capability-grants"
              ]
            },
            "description": "grantApplicationCapability\n\nGrants one capability to one application for a bounded period.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Revoke an application's capability grant",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/capability-grants/{{capability_grant_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "capability-grants",
                "{{capability_grant_id}}",
                "revocation"
              ]
            },
            "description": "revokeApplicationCapability\n\nRevokes one grant with immediate effect. Tokens already issued that\ncarry the corresponding scope stop being honoured at once; revocation is\nevaluated per request rather than waiting for a token to expire.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List an application's OAuth client credentials",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/credentials",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "credentials"
              ]
            },
            "description": "listApplicationCredentials\n\nReturns the OAuth client credentials of one application: client\nidentifier, state, creation and expiry times, and last-used time."
          }
        },
        {
          "name": "Create or confirm the application's OAuth client",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/credentials",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "credentials"
              ]
            },
            "description": "issueApplicationCredential\n\n**There is no client secret** (D95). The application authenticates to\nthe token endpoint with `private_key_jwt` — an assertion signed with\nits workload certificate's private key, which never leaves the\norganization — and this operation creates the OAuth client that\naccepts those assertions, or confirms the one it has. The client's keys\nare exactly the public keys of the application's active workload\ncertificates, kept in step by the platform: issuing a certificate adds\nits key, revoking one removes it.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Revoke an OAuth client credential",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/credentials/{{credential_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "credentials",
                "{{credential_id}}",
                "revocation"
              ]
            },
            "description": "revokeApplicationCredential\n\nRevokes one client credential immediately. Tokens already issued under\nit stop being accepted; the platform does not wait for them to expire,\nbecause a credential is revoked precisely when its tokens can no longer\nbe trusted.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List an application's workload certificates",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/workload-certificates",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "workload-certificates"
              ]
            },
            "description": "listWorkloadCertificates\n\nReturns the client certificates bound to this application, newest first\nby default, with their state, validity window and overlap window."
          }
        },
        {
          "name": "Request a workload certificate",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/workload-certificates",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "workload-certificates"
              ]
            },
            "description": "requestWorkloadCertificate\n\nSubmits a certificate signing request and obtains a client certificate\nthat authenticates this one application in this one environment.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one workload certificate",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/workload-certificates/{{workload_certificate_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "workload-certificates",
                "{{workload_certificate_id}}"
              ]
            },
            "description": "getWorkloadCertificate\n\nReturns one workload certificate, including the issued certificate chain\nin PEM once issuance has completed. Poll this after a `201` in\n`requested`, or wait for `client_certificate.issued`."
          }
        },
        {
          "name": "Revoke a workload certificate",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/workload-certificates/{{workload_certificate_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "workload-certificates",
                "{{workload_certificate_id}}",
                "revocation"
              ]
            },
            "description": "revokeWorkloadCertificate\n\nRevokes one workload certificate immediately. Connections presenting it\nare refused from that moment; there is no grace period, because\nrevocation on suspected compromise that takes effect later is not\nrevocation.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List an application's webhook endpoints",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints"
              ]
            },
            "description": "listWebhookEndpoints\n\nReturns the endpoints registered to receive events for this application,\nwith their state, subscribed event types and the outcome of the most\nrecent verification attempt."
          }
        },
        {
          "name": "Register a webhook endpoint",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints"
              ]
            },
            "description": "registerWebhookEndpoint\n\nRegisters an endpoint to receive events for this application. The\nendpoint is created in `pending_verification` and **receives no events\nuntil control of it has been proven** through `verifyWebhookEndpoint`.\nRegistering an address one does not control must never be enough to\nstart receiving another organization's event stream.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one webhook endpoint",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints/{{webhook_endpoint_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints",
                "{{webhook_endpoint_id}}"
              ]
            },
            "description": "getWebhookEndpoint\n\nReturns one endpoint with its state, subscribed event types, the outcome\nof the most recent verification attempt and the location at which event\nverification keys are published."
          }
        },
        {
          "name": "Update a webhook endpoint",
          "request": {
            "method": "PATCH",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints/{{webhook_endpoint_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints",
                "{{webhook_endpoint_id}}"
              ]
            },
            "description": "updateWebhookEndpoint\n\nUpdates the endpoint's description or its subscribed event types.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Disable a webhook endpoint",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints/{{webhook_endpoint_id}}/disablement",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints",
                "{{webhook_endpoint_id}}",
                "disablement"
              ]
            },
            "description": "disableWebhookEndpoint\n\nStops delivery to an endpoint. No further events are queued for it and\nit moves to `disabled`.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Verify control of a webhook endpoint",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/applications/{{application_id}}/webhook-endpoints/{{webhook_endpoint_id}}/verification",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "applications",
                "{{application_id}}",
                "webhook-endpoints",
                "{{webhook_endpoint_id}}",
                "verification"
              ]
            },
            "description": "verifyWebhookEndpoint\n\nProves control of a registered endpoint and activates it."
          }
        }
      ]
    },
    {
      "name": "Sandbox",
      "item": [
        {
          "name": "List the sandbox scenarios and the subscribers that trigger them",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/sandbox-scenarios",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "sandbox-scenarios"
              ]
            },
            "description": "listSandboxScenarios\n\nEach scenario is triggered by **subscriber identity alone** (D123): use\nthe listed synthetic subscriber in an ordinary call and the platform\nproduces that outcome. There is no header, console switch or clock to\nset. The subscribers are related to every sandbox organization when it\nis created, and they never exist in production."
          }
        }
      ]
    },
    {
      "name": "Certificates",
      "item": [
        {
          "name": "List certificates",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates"
              ]
            },
            "description": "listCertificates\n\nLists the certificates visible to the calling organization, newest\nissuance first. This collection is a working list rather than a\nsequence, so it defaults to `sort=issued_at` with `order=desc`."
          }
        },
        {
          "name": "Retrieve a certificate",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}"
              ]
            },
            "description": "getCertificate\n\nReturns one certificate: its X.509 material, its current lifecycle\nstatus, every interval during which it was on hold, any live suspension\nwith its statutory deadlines, any revocation, and its regulatory\nsubmission record."
          }
        },
        {
          "name": "Determine certificate status as at a past moment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/status-at",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "status-at"
              ]
            },
            "description": "getCertificateStatusAtTime\n\nAnswers the only question that matters about a signature already made:\n**was this certificate usable for signing at that instant?**"
          }
        },
        {
          "name": "List certificate status history",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/status-history",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "status-history"
              ]
            },
            "description": "listCertificateStatusHistory\n\nEvery lifecycle transition this certificate has undergone, oldest first:\nthe hold imposed at issuance and its release, each suspension and each\nrelease, withdrawal, revocation and expiry."
          }
        },
        {
          "name": "List hold intervals",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/hold-intervals",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "hold-intervals"
              ]
            },
            "description": "listCertificateHoldIntervals\n\nEvery interval during which this certificate was on hold, with its start\nand, where the hold has ended, its end."
          }
        },
        {
          "name": "Release the hold on a certificate",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/hold-release",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "hold-release"
              ]
            },
            "description": "releaseCertificateHold\n\nRecords receipt of the completed, signed application form and releases\nthe hold. The certificate moves from `issued_on_hold` to `active` and\nbecomes usable for signing from the moment the hold interval closes.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Withdraw a certificate still on hold",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/withdrawal",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "withdrawal"
              ]
            },
            "description": "withdrawCertificate\n\nWithdraws a certificate whose signed application form will not arrive.\nPermitted only while the certificate is on hold.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Report that a private key has been disclosed or compromised",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/compromise-report",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "compromise-report"
              ]
            },
            "description": "reportCertificateCompromise\n\nReports that the private key corresponding to this certificate has been\ndisclosed to, or may have been obtained by, a person not authorized to\naffix the subscriber's signature.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List compromise reports for a certificate",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/compromise-reports",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "compromise-reports"
              ]
            },
            "description": "listCertificateCompromiseReports\n\nEvery compromise report received for this certificate, oldest first,\neach linked to the suspension it caused."
          }
        },
        {
          "name": "Suspend a certificate",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/suspension",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "suspension"
              ]
            },
            "description": "suspendCertificate\n\nOpens a suspension against an active certificate on a recorded ground.\nA suspended certificate cannot be used for signing, and signatures\nattempted while it is suspended are not valid.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List suspensions of a certificate",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/suspensions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "suspensions"
              ]
            },
            "description": "listCertificateSuspensions\n\nEvery suspension opened against this certificate, oldest first, live or\nconcluded, with the interval during which the certificate was actually\nsuspended."
          }
        },
        {
          "name": "Release a suspension",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/suspension-release",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "suspension-release"
              ]
            },
            "description": "releaseCertificateSuspension\n\nCloses a live suspension and returns the certificate to `active`,\nbecause investigation did not establish the ground on which it was\nsuspended.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve the revocation record",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "revocation"
              ]
            },
            "description": "getCertificateRevocation\n\nReturns the revocation record for a revoked or withdrawn certificate:\nthe ground, the effective time, who requested it, when it was published,\nand the suspension it followed where it followed one."
          }
        },
        {
          "name": "Revoke a certificate",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "revocation"
              ]
            },
            "description": "revokeCertificate\n\nRevokes the certificate on a stated statutory ground, with a stated\neffective time.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve the reissuance record",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/reissuance",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "reissuance"
              ]
            },
            "description": "getCertificateReissuance\n\nReturns the reissuance record in which this certificate is the\npredecessor: the disposal route taken, the revocation that resulted, the\nenrollment opened for the successor, and the successor certificate once\nit has been issued."
          }
        },
        {
          "name": "Request reissuance, revoking the predecessor",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/reissuance",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "reissuance"
              ]
            },
            "description": "requestCertificateReissuance\n\nRequests a successor certificate for this subscriber and disposes of\nthis one.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve the regulatory submission record",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificates/{{certificate_id}}/regulatory-submission",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificates",
                "{{certificate_id}}",
                "regulatory-submission"
              ]
            },
            "description": "getCertificateRegulatorySubmission\n\nReturns whether this certificate has been submitted to the regulator,\nwhich holds a record of every certificate issued and a database of every\npublic key."
          }
        },
        {
          "name": "List the certificate profiles this organization may enroll against",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificate-profiles",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificate-profiles"
              ]
            },
            "description": "listCertificateProfiles\n\nReturns the profiles permitted to the calling organization in the\ncurrent environment."
          }
        },
        {
          "name": "Retrieve one certificate profile",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/certificate-profiles/{{profile_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "certificate-profiles",
                "{{profile_id}}"
              ]
            },
            "description": "getCertificateProfile\n\nReturns the profile with its version, the class and type it expresses,\nthe validity periods it offers, the identity evidence it requires, and\nwhether it requires an attested device."
          }
        }
      ]
    },
    {
      "name": "Deliveries",
      "item": [
        {
          "name": "List credential deliveries",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-deliveries",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-deliveries"
              ]
            },
            "description": "listCredentialDeliveries\n\nLists deliveries visible to the calling organization, most recently\ncreated first. Filters narrow the list to one certificate, subscriber,\ndevice or state."
          }
        },
        {
          "name": "Create a credential delivery",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-deliveries",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-deliveries"
              ]
            },
            "description": "createCredentialDelivery\n\nOpens a short-lived authorization to deliver the first copy of a\ncredential to one registered application on one registered device.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve a credential delivery",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-deliveries/{{delivery_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-deliveries",
                "{{delivery_id}}"
              ]
            },
            "description": "getCredentialDelivery\n\nReturns the delivery record: its state, target binding, expiry, attempt\ncounters, authorization evidence, import confirmation and retirement\noutcome."
          }
        },
        {
          "name": "Retire a delivery and destroy retained material",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-deliveries/{{delivery_id}}/retire",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-deliveries",
                "{{delivery_id}}",
                "retire"
              ]
            },
            "description": "retireCredentialDelivery\n\nDestroys any key material the platform still holds for this delivery and\nrecords destruction evidence, moving the delivery to `retired`.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Cancel a credential delivery",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-deliveries/{{delivery_id}}/cancel",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-deliveries",
                "{{delivery_id}}",
                "cancel"
              ]
            },
            "description": "cancelCredentialDelivery\n\nCancels a delivery that has not yet been retrieved, moving it to\n`cancelled`. Any package built for it is destroyed and can never be\nretrieved.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    },
    {
      "name": "Transfers",
      "item": [
        {
          "name": "List credential transfers",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-transfers",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-transfers"
              ]
            },
            "description": "listCredentialTransfers\n\nLists transfer records visible to the calling organization, most\nrecently created first, including those the platform refused to relay."
          }
        },
        {
          "name": "Retrieve a credential transfer",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-transfers/{{transfer_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-transfers",
                "{{transfer_id}}"
              ]
            },
            "description": "getCredentialTransfer\n\nReturns the transfer record: the offer, both parties, the transcript\nhash, whether the platform relayed it or merely learned of it, any\nrefusal, and the completion report."
          }
        }
      ]
    },
    {
      "name": "Devices",
      "item": [
        {
          "name": "List where a credential is held",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-copies",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-copies"
              ]
            },
            "description": "listCredentialCopies\n\nLists the applications and devices reported to hold a copy of a\ncredential."
          }
        },
        {
          "name": "Retrieve a reported credential copy",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/credential-copies/{{copy_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "credential-copies",
                "{{copy_id}}"
              ]
            },
            "description": "getCredentialCopy\n\nReturns one inventory record: which application on which device\nreported holding the credential, how the copy arrived, the at-rest\nprotection it reported, and any de-provisioning instruction."
          }
        },
        {
          "name": "List the devices registered to a subscriber",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/devices",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "devices"
              ]
            },
            "description": "listRegisteredDevices\n\nReturns every device registered to the subscriber, including retired\nones, so that an integrator can reconcile delivery targets. Retirement\nis recorded rather than deleted: a delivery made to a device that was\nlater retired remains evidenced.\n"
          }
        },
        {
          "name": "Register a subscriber-controlled device that may receive credentials",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/devices",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "devices"
              ]
            },
            "description": "registerDevice\n\nRegisters an installation identified by a device-bound public key, so\nthat a credential may later be delivered to it.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one registered device",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/devices/{{device_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "devices",
                "{{device_id}}"
              ]
            },
            "description": "getRegisteredDevice\n\nReturns the device, its binding to a subscriber, its attestation outcome\nwhere one was supplied, and its status.\n"
          }
        },
        {
          "name": "Retire a registered device so that it may receive no further credentials",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/devices/{{device_id}}/retirement",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "devices",
                "{{device_id}}",
                "retirement"
              ]
            },
            "description": "retireRegisteredDevice\n\nMarks the device as no longer a permitted delivery target. This is a\ncommand, not a status edit, and it is not reversible: a replaced or lost\ndevice is retired and a new one registered.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    },
    {
      "name": "Organizations",
      "item": [
        {
          "name": "List organizations visible to the caller",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations"
              ]
            },
            "description": "listOrganizations\n\nReturns the organizations this request is permitted to see. For an\nordinary consuming organization that is exactly one — its own — because\nan application resolves to a single organization. A delegated management\nchannel operating an explicitly granted management delegation sees the\norganizations within the scope of that delegation and no others."
          }
        },
        {
          "name": "Retrieve one organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}"
              ]
            },
            "description": "getOrganization\n\nReturns the organization record: lifecycle state, verification state and\nexpiry, category, contacts and the authorized signatory of record."
          }
        },
        {
          "name": "List verification submissions for an organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/verification-submissions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "verification-submissions"
              ]
            },
            "description": "listOrganizationVerificationSubmissions\n\nReturns the history of verification submissions with the outcome of\neach, **oldest first** by default: this is a sequence rather than a\nfeed, and it reads correctly in the order the submissions and reviews\nhappened. Pass `order=desc` for the most recent first."
          }
        },
        {
          "name": "Submit refreshed verification evidence",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/verification-submissions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "verification-submissions"
              ]
            },
            "description": "submitOrganizationVerification\n\nSubmits refreshed legal-entity evidence for an organization whose\nverification has lapsed or is approaching expiry. **Verification is\nrevalidated, not permanent**: a verified status carries an expiry, and\nlapsed verification suspends authority without affecting certificates\nalready issued.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Upload a document for the organization's verification",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/verification-documents",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "verification-documents"
              ]
            },
            "description": "uploadVerificationDocument\n\nOne document behind the organization's verification: a registration\ncertificate, a letter of appointment. The body is the file itself (PDF,\nPNG or JPEG, at most 10 MB), its type in `Content-Type` and its name in\n`filename`. It is stored encrypted and answered with its reference\n(`evd_…`), which a verification submission then cites; the submission\nattaches it, and only this organization can cite it. A document no\nsubmission cites within a day is deleted.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Open a document the organization uploaded for its verification",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/verification-documents/{{document_id}}/content",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "verification-documents",
                "{{document_id}}",
                "content"
              ]
            },
            "description": "getVerificationDocumentContent\n\nThe file itself, as uploaded, for the organization to check what it\nfiled. Only documents this organization uploaded are served; any other\nreference is `404`. Every open is recorded in the audit trail. The\nresponse is never cached.\n"
          }
        },
        {
          "name": "List an organization's capability grants",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/capability-grants",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "capability-grants"
              ]
            },
            "description": "listOrganizationCapabilityGrants\n\nReturns the capabilities granted to the organization, per environment,\nwith the effective period, the reason and the granting actor."
          }
        },
        {
          "name": "List an organization's permitted certificate profiles",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/organizations/{{organization_id}}/certificate-profile-permissions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "organizations",
                "{{organization_id}}",
                "certificate-profile-permissions"
              ]
            },
            "description": "listCertificateProfilePermissions\n\nReturns the certificate profiles the organization is permitted to enrol\nsubscribers under, per environment."
          }
        },
        {
          "name": "List environment promotion requests",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/environment-promotions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "environment-promotions"
              ]
            },
            "description": "listEnvironmentPromotions\n\nReturns the promotion requests raised by the organizations visible to\nthe caller, newest first by default, each with its readiness checks and\noutcome.\n"
          }
        },
        {
          "name": "Request promotion to production",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/environment-promotions",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "environment-promotions"
              ]
            },
            "description": "requestEnvironmentPromotion\n\nRaises a request to promote a sandbox integration to production.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one promotion request",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/environment-promotions/{{promotion_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "environment-promotions",
                "{{promotion_id}}"
              ]
            },
            "description": "getEnvironmentPromotion\n\nReturns one promotion request with its current readiness checks, any\nreported configuration drift, and the decision where one has been taken."
          }
        },
        {
          "name": "Withdraw a promotion request",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/environment-promotions/{{promotion_id}}/withdrawal",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "environment-promotions",
                "{{promotion_id}}",
                "withdrawal"
              ]
            },
            "description": "withdrawEnvironmentPromotion\n\nWithdraws a promotion request that is still under review, for instance\nwhere the integrator has found a defect and would rather resubmit than\nbe assessed as they are.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    },
    {
      "name": "Activity",
      "item": [
        {
          "name": "Recent requests made by this organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/activity",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "activity"
              ]
            },
            "description": "listActivityRecords\n\nThe calling organization's own recent requests, so that an integrator\ncan answer \"what did my integration just do, and why did that fail\"\nwithout opening a support ticket. Most integration failures are\ndiagnosed from the request identifier alone."
          }
        },
        {
          "name": "One activity record",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/activity/{{activity_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "activity",
                "{{activity_id}}"
              ]
            },
            "description": "getActivityRecord\n\nOne request the calling organization made, for debugging a single\nfailure."
          }
        }
      ]
    },
    {
      "name": "Usage",
      "item": [
        {
          "name": "Recorded billable operations",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/records",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "records"
              ]
            },
            "description": "listUsageRecords\n\nThe individual billable operations recorded for the calling\norganization — the records the periods in `listUsagePeriods` are\naggregated from, and the level at which a discrepancy is finally chased\nto a single operation."
          }
        },
        {
          "name": "One recorded billable operation",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/records/{{usage_record_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "records",
                "{{usage_record_id}}"
              ]
            },
            "description": "getUsageRecord\n\nOne usage record, for reconciling a single line against the operation\nthat produced it — the end of the trail that starts with a period total\nthat does not match, narrows through a reconciliation line, and finishes\nhere at one operation."
          }
        },
        {
          "name": "Pre-aggregated usage periods",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/periods",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "periods"
              ]
            },
            "description": "listUsagePeriods\n\nUsage totals for the calling organization, pre-aggregated into\ntime-window periods."
          }
        },
        {
          "name": "One usage period",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/periods/{{usage_period_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "periods",
                "{{usage_period_id}}"
              ]
            },
            "description": "getUsagePeriod\n\nOne pre-aggregated usage period with its per-operation lines, its\nadjustments, and the basis it was computed on."
          }
        },
        {
          "name": "Additive corrections to closed usage periods",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/adjustments",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "adjustments"
              ]
            },
            "description": "listUsageAdjustments\n\nCorrections to usage, as records in their own right."
          }
        },
        {
          "name": "One usage adjustment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/adjustments/{{adjustment_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "adjustments",
                "{{adjustment_id}}"
              ]
            },
            "description": "getUsageAdjustment\n\nOne additive correction, with what it corrects and why."
          }
        },
        {
          "name": "Check the platform's arithmetic against your own",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/usage/reconciliation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "usage",
                "reconciliation"
              ]
            },
            "description": "getUsageReconciliation\n\nThe three counts an organization needs in order to check this\nplatform's arithmetic for itself, and the gaps between them."
          }
        }
      ]
    },
    {
      "name": "Audit",
      "item": [
        {
          "name": "Audit entries concerning this organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/entries",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "entries"
              ]
            },
            "description": "listAuditEntries\n\nAudit entries in which the calling organization was the actor or the\nsubject, in append order by `leaf_index`."
          }
        },
        {
          "name": "One audit entry",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/entries/{{audit_entry_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "entries",
                "{{audit_entry_id}}"
              ]
            },
            "description": "getAuditEntry\n\nOne audit entry with its leaf position and leaf hash, so that a single\nentry can be proven to be in the log without downloading a page."
          }
        },
        {
          "name": "Prove one audit entry is in the log",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/entries/{{audit_entry_id}}/inclusion-proof",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "entries",
                "{{audit_entry_id}}",
                "inclusion-proof"
              ]
            },
            "description": "getAuditInclusionProof\n\nThe Merkle audit path proving that this entry is a leaf of the audit log\nat a stated published signed tree head."
          }
        },
        {
          "name": "Prove the audit log has only ever been appended to",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/consistency-proof",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "consistency-proof"
              ]
            },
            "description": "getAuditConsistencyProof\n\nThe proof that the log at a later signed tree head is an append-only\nextension of the log at an earlier one: same leaves, same order, nothing\nremoved, nothing rewritten."
          }
        },
        {
          "name": "Published signed tree heads",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/tree-heads",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "tree-heads"
              ]
            },
            "description": "listAuditTreeHeads\n\nThe signed tree heads over the audit log: each a root hash, a tree size\nand a signature, published so that anyone can check the log is\nappend-only without being shown anything in it."
          }
        },
        {
          "name": "One published signed tree head",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/audit/tree-heads/{{tree_head_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "audit",
                "tree-heads",
                "{{tree_head_id}}"
              ]
            },
            "description": "getAuditTreeHead\n\nOne published head, for comparison against a copy recorded when it was\npublished."
          }
        }
      ]
    },
    {
      "name": "Reports",
      "item": [
        {
          "name": "Reports submitted by this organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/reports",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "reports"
              ]
            },
            "description": "listReports\n\nReports the calling organization has submitted, including those whose\nresults have expired."
          }
        },
        {
          "name": "Submit a report for generation",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/reports",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "reports"
              ]
            },
            "description": "submitReport\n\nSubmit a request for a defensible extract over a period. Generation is\nasynchronous.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "One report and its generation status",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/reports/{{report_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "reports",
                "{{report_id}}"
              ]
            },
            "description": "getReport\n\nThe state of one report: whether it is queued, generating, available,\nexpired or failed, and the basis it was generated on."
          }
        },
        {
          "name": "Retrieve a generated report",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/reports/{{report_id}}/content",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "reports",
                "{{report_id}}",
                "content"
              ]
            },
            "description": "getReportContent\n\nRetrieve the generated extract."
          }
        }
      ]
    },
    {
      "name": "Dashboards",
      "item": [
        {
          "name": "A metric over time, at a fixed granularity",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/dashboards/time-series",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "dashboards",
                "time-series"
              ]
            },
            "description": "getDashboardTimeSeries\n\nOne metric bucketed over time, for display."
          }
        },
        {
          "name": "A metric grouped by one permitted dimension",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/dashboards/breakdown",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "dashboards",
                "breakdown"
              ]
            },
            "description": "getDashboardBreakdown\n\nOne metric for one period, grouped by one dimension from a fixed set."
          }
        },
        {
          "name": "The leading values of one dimension for a metric",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/dashboards/top",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "dashboards",
                "top"
              ]
            },
            "description": "getDashboardTopN\n\nThe highest-ranked values of one permitted dimension for one metric over\none period — the third and last of the canonical dashboard shapes,\nalongside a time series and a grouping. There is no fourth, and there is\nno general query language."
          }
        }
      ]
    },
    {
      "name": "Signing",
      "item": [
        {
          "name": "List signature requests",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/signature-requests",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "signature-requests"
              ]
            },
            "description": "listSignatureRequests\n\nLists signature requests created by the calling organization, most recently\ncreated first. Filters narrow the list to one subscriber, certificate,\nstatus or creation date range."
          }
        },
        {
          "name": "Create a signature request",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/signature-requests",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "signature-requests"
              ]
            },
            "description": "createSignatureRequest\n\nOpens a new signature request over a document hash, binding it to a subscriber\nand establishing the terms under which it may be signed.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve a signature request",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/signature-requests/{{request_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "signature-requests",
                "{{request_id}}"
              ]
            },
            "description": "getSignatureRequest\n\nReturns the request record in full: its state, hash, presentation digest,\nauthorization evidence, and signature value if complete."
          }
        },
        {
          "name": "Record the presentation digest",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/signature-requests/{{request_id}}/record-presentation-digest",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "signature-requests",
                "{{request_id}}",
                "record-presentation-digest"
              ]
            },
            "description": "recordSignaturePresentationDigest\n\nRecords a digest of what was actually shown to the subscriber when the\ndocument was presented. This establishes, as much as cryptography can,\nthat the subscriber saw a rendering that matched the document hash.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Request an authorization challenge",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/signature-requests/{{request_id}}/authorization-challenge",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "signature-requests",
                "{{request_id}}",
                "authorization-challenge"
              ]
            },
            "description": "requestAuthorizationChallenge\n\nRequests that an authorization challenge be sent to the subscriber's\nregistered channel (email or mobile), **only if** the request requires\nauthorization evidence (`require_authorization_evidence: true`).",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    },
    {
      "name": "Subscribers",
      "item": [
        {
          "name": "Resolve a subscriber from verified identifiers, creating one where none matches",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/resolution",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "resolution"
              ]
            },
            "description": "resolveSubscriber\n\nFinds the platform's stable record for a natural person, creating one\nwhere no existing record matches.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List subscribers visible to the calling organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers"
              ]
            },
            "description": "listSubscribers\n\nReturns the subscribers for which the calling organization has a\nrecorded relationship, newest first."
          }
        },
        {
          "name": "Retrieve one subscriber",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}"
              ]
            },
            "description": "getSubscriber\n\nReturns the subscriber record: its platform identity, status, and counts\nof the material hanging off it. Verified identifiers and verified\ncontact channels are retrieved through their own sub-resources, which\napply their own redaction rules."
          }
        },
        {
          "name": "List the verified identifiers held against a subscriber",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/identifiers",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "identifiers"
              ]
            },
            "description": "listSubscriberVerifiedIdentifiers\n\nReturns what the platform has verified about who this subscriber is, so\nthat an integrator can reconcile its own record against the platform's\nwithout re-submitting evidence."
          }
        },
        {
          "name": "List a subscriber's verified contact channels, by reference only",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/contact-channels",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "contact-channels"
              ]
            },
            "description": "listSubscriberContactChannels\n\nReturns the channels verified at enrollment that may carry an\nauthorization challenge at signing time."
          }
        },
        {
          "name": "Claim a contact channel and send a one-time code to it",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/contact-channels/registration",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "contact-channels",
                "registration"
              ]
            },
            "description": "registerSubscriberContactChannel\n\nClaims a channel for a subscriber, sends a one-time code to it, and\nreturns the reference the code will be verified against. The channel is\n**pending** until `verifySubscriberContactChannel` succeeds: it does not\nappear in the listing, may not be named in an enrollment, and carries no\nauthorization challenge.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Send the subscriber a code to authorize the calling application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/application-authorization-challenges",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "application-authorization-challenges"
              ]
            },
            "description": "requestApplicationAuthorizationChallenge\n\nStarts an application authorization: a code is sent to one of the\nsubscriber's verified contact channels, naming the calling\napplication. The subscriber authorizes it by giving the code back\nthrough `grantApplicationAuthorization`.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "The calling organization's authorizations from one subscriber",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/application-authorizations",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "application-authorizations"
              ]
            },
            "description": "listApplicationAuthorizations\n\nNewest first, active and revoked. Another organization's are never shown."
          }
        },
        {
          "name": "Record the subscriber's authorization of the calling application",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/application-authorizations",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "application-authorizations"
              ]
            },
            "description": "grantApplicationAuthorization\n\nRecords that the subscriber authorized the calling application to act\nfor them, on the strength of the code they received. The application\nauthorized is always the caller's own; there is no field to name\nanother. From then on the application's organization-minted subscriber\ntokens for this subscriber are accepted, until the authorization is\nrevoked.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Revoke an application authorization",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/application-authorizations/{{authorization_id}}/revocation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "application-authorizations",
                "{{authorization_id}}",
                "revocation"
              ]
            },
            "description": "revokeApplicationAuthorization\n\nEnds the authorization. The application's next subscriber token for\nthis subscriber is refused. Revocation is permanent; authorizing again\nis a new grant with new evidence. An authorization that is absent,\nanother organization's, or already revoked returns the same `404`.\n"
          }
        },
        {
          "name": "Prove a claimed channel by returning the code sent to it",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/subscribers/{{subscriber_id}}/contact-channels/{{channel_id}}/verification",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "subscribers",
                "{{subscriber_id}}",
                "contact-channels",
                "{{channel_id}}",
                "verification"
              ]
            },
            "description": "verifySubscriberContactChannel\n\nAnswers the challenge raised when the channel was claimed. On success\nthe channel becomes verified, appears in the listing, and may be named\nin an enrollment.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    },
    {
      "name": "Enrollments",
      "item": [
        {
          "name": "List enrollments opened by the calling organization",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments"
              ]
            },
            "description": "listEnrollments\n\nReturns the organization's enrollments, newest first. Filter by status to\nbuild a work queue: \"information_requested\" is the status that needs the\norganization to act, and \"confirmation_pending\" is the status that needs\nthe applicant to act.\n"
          }
        },
        {
          "name": "Open an enrollment carrying the statutory application content",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments"
              ]
            },
            "description": "createEnrollment\n\nCreates an enrollment in draft under one certificate profile.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve one enrollment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}"
              ]
            },
            "description": "getEnrollment\n\nReturns the enrollment with its current status, the statutory\napplication content, and the evidence attached so far."
          }
        },
        {
          "name": "Replace the statutory application content of a draft enrollment",
          "request": {
            "method": "PUT",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/application",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "application"
              ]
            },
            "description": "replaceEnrollmentApplication\n\nReplaces the application content wholesale while the enrollment is still\nin draft, so that a transcription error can be corrected without\ndiscarding the consent and attestations already attached.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "File the application and start the statutory decision timer",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/submission",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "submission"
              ]
            },
            "description": "submitEnrollment\n\nMoves the enrollment from draft to submitted. This is the act of filing\nthe application, and it is the event from which the statutory decision\nperiod runs: the authority must issue or reject within that period, and\na rejection must carry reasons.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List the identity attestations attached to an enrollment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/attestations",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "attestations"
              ]
            },
            "description": "listEnrollmentIdentityAttestations\n\nReturns every attestation attached to the enrollment, oldest first,\nincluding any that a later attestation superseded. Nothing is removed\nfrom this list, because the sequence of what was asserted and when is\nitself part of the evidence.\n"
          }
        },
        {
          "name": "Attest verified identity and supply evidence references",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/attestations",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "attestations"
              ]
            },
            "description": "addEnrollmentIdentityAttestation\n\nRecords that the organization has performed identity proofing for this\napplicant, by a stated method at a stated assurance level, and names the\nevidence it holds.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List the consent records held against an enrollment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/consent",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "consent"
              ]
            },
            "description": "listEnrollmentConsentRecords\n\nReturns every consent record for the enrollment, oldest first. The list\nonly grows: a consent record is never amended and never disappears.\n"
          }
        },
        {
          "name": "Record the subscriber's acceptance of the enrollment terms",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/consent",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "consent"
              ]
            },
            "description": "recordEnrollmentConsent\n\nRecords what the subscriber was shown and accepted: which version of the\nenrollment terms, in which language, over which channel, under what\nauthentication, and the digest of exactly what was rendered to them.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "List the authority's requests for further detail on an enrollment",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/information-requests",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "information-requests"
              ]
            },
            "description": "listEnrollmentInformationRequests\n\nReturns the information requests raised against the enrollment."
          }
        },
        {
          "name": "Answer an information request raised against an enrollment",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/information-responses",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "information-responses"
              ]
            },
            "description": "respondToEnrollmentInformationRequest\n\nSupplies the further detail the authority asked for, against one named\ninformation request.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Recommend a verified enrollment for the authority's decision",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/recommendation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "recommendation"
              ]
            },
            "description": "recommendEnrollment\n\nRecords the organization's recommendation that the enrollment proceed.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Retrieve the proposed certificate contents for the applicant to verify",
          "request": {
            "method": "GET",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/proposed-contents",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "proposed-contents"
              ]
            },
            "description": "getProposedCertificateContents\n\nReturns exactly what the authority proposes to put in the certificate,\nso that it can be shown to the applicant before issuance."
          }
        },
        {
          "name": "Record the applicant's statutory confirmation of the proposed contents",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/confirmation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "confirmation"
              ]
            },
            "description": "confirmProposedCertificateContents\n\nRecords that the applicant was shown the proposed certificate contents\nand confirmed them. The enrollment moves from \"confirmation_pending\" to\n\"confirmed\".",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        },
        {
          "name": "Cancel an enrollment before issuance",
          "request": {
            "method": "POST",
            "header": [
              {
                "key": "Accept",
                "value": "application/json"
              },
              {
                "key": "Correlation-Id",
                "value": "{{$guid}}"
              },
              {
                "key": "Authorization",
                "value": "Bearer {{access_token}}"
              },
              {
                "key": "Idempotency-Key",
                "value": "{{$guid}}"
              },
              {
                "key": "Content-Type",
                "value": "application/json"
              }
            ],
            "url": {
              "raw": "{{base_url}}/v1/enrollments/{{enrollment_id}}/cancellation",
              "host": [
                "{{base_url}}"
              ],
              "path": [
                "v1",
                "enrollments",
                "{{enrollment_id}}",
                "cancellation"
              ]
            },
            "description": "cancelEnrollment\n\nTerminates the enrollment at the applicant's or the organization's\ninstance. Cancellation is explicit, final and available at any point\nbefore issuance; it is not an undo of the previous step.",
            "body": {
              "mode": "raw",
              "raw": "{}",
              "options": {
                "raw": {
                  "language": "json"
                }
              }
            }
          }
        }
      ]
    }
  ]
}
