`POST /v1/orgs/{org}/enrollment-tokens`.
const url = 'https://api.updawg.net/v1/orgs/example/enrollment-tokens';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"expires_at":"2026-04-15T12:00:00Z","labels":{"additionalProperty":"example"},"max_uses":1,"name":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.updawg.net/v1/orgs/example/enrollment-tokens \ --header 'Content-Type: application/json' \ --data '{ "expires_at": "2026-04-15T12:00:00Z", "labels": { "additionalProperty": "example" }, "max_uses": 1, "name": "example" }'Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
Request Bodyrequired
Section titled “Request Bodyrequired”object
When it stops working. Absent never expires.
Put on every host that enrols with it.
object
How many hosts it may enrol. Absent is unlimited.
What it is for — “web tier”, “laptop test”. Shown in the list, since the value never is again.
Examplegenerated
{ "expires_at": "2026-04-15T12:00:00Z", "labels": { "additionalProperty": "example" }, "max_uses": 1, "name": "example"}Responses
Section titled “Responses”Issued. ⚠️ token is in this response and never again.
The one response that carries the value.
object
etk_…. The record, not the credential.
object
Whether an agent presenting it now would be let in: not revoked, not expired, not used up. The same three conditions the gateway checks, so the portal does not have to know them.
Hosts that enrolled with it and then checked in. A use is charged on the first check-in, not when the certificate is issued, so an attempt the agent refused costs nothing (DAWG-224).
⚠️ Shown once. enr_…. Only its hash is kept.
Examplegenerated
{ "created_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "id": "example", "labels": { "additionalProperty": "example" }, "max_uses": 1, "name": "example", "revoked_at": "2026-04-15T12:00:00Z", "usable": true, "uses": 1, "token": "example"}No name, a limit below one, an expiry in the past, or labels that are not a small map of non-empty keys.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted for this role.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such organization, or not yours — one answer for both.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}