Ga naar inhoud

Apply for membership

POST
/api/v1/onboarding/applications
curl --request POST \
--url https://example.com/api/v1/onboarding/applications \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true } }'

Sent by the applicant’s connector, with a DCP token signed by the DID that applies (proof of control over the DID). The authority sends the signatory the rulebook declaration and the mandate to sign. One open application per DID: an existing one is returned.

Media typeapplication/json

What an applicant’s connector declares.

object
did
required
string
slug
required
string
name
required
string
legal_name
required
string
kvk_number
required
string
contact_email
string | null
requested_roles

Ignored with an invite: its roles count.

Array<string>
dsp_endpoint
required
string
dataplane_url
string | null
color
string | null
invite_code
string | null
signatory_name

Person authorised to sign on behalf of the organisation (KvK).

string | null
signatory_email
string | null
key_storage
One of:
null

Example generated

{
"did": "example",
"slug": "example",
"name": "example",
"legal_name": "example",
"kvk_number": "example",
"contact_email": "example",
"requested_roles": [
"example"
],
"dsp_endpoint": "example",
"dataplane_url": "example",
"color": "example",
"invite_code": "example",
"signatory_name": "example",
"signatory_email": "example",
"key_storage": {
"source": "example",
"non_exportable": true
}
}

OK.

Media typeapplication/json

An application as the API shows it: documents the JSON built in [application_json].

object
did
required
string
slug
required
string
name
required
string
legal_name
required
string
kvk_number
required
string
contact_email
string | null
requested_roles

Ignored with an invite: its roles count.

Array<string>
dsp_endpoint
required
string
dataplane_url
string | null
color
string | null
invite_code
string | null
signatory_name

Person authorised to sign on behalf of the organisation (KvK).

string | null
signatory_email
string | null
key_storage
One of:
null
id
required
string
state
required

awaiting_signature, pending, approved or rejected.

string
roles
required

The roles asked for, or those of the invite; after approval the granted ones.

Array<string>
granted_roles

Approved only.

Array<string> | null
reason

Why it was rejected.

string | null
decided_by
string | null
decided_at
string | null format: date-time
created_at
required
string format: date-time
submitted_at
required
string format: date-time
review

The check of the reviewer: kvk_verified, verified_by, verified_at, note, signer.

object | null
signing

The latest signing request of the signatory.

object | null

Example generated

{
"did": "example",
"slug": "example",
"name": "example",
"legal_name": "example",
"kvk_number": "example",
"contact_email": "example",
"requested_roles": [
"example"
],
"dsp_endpoint": "example",
"dataplane_url": "example",
"color": "example",
"invite_code": "example",
"signatory_name": "example",
"signatory_email": "example",
"key_storage": {
"source": "example",
"non_exportable": true
},
"id": "example",
"state": "example",
"roles": [
"example"
],
"granted_roles": [
"example"
],
"reason": "example",
"decided_by": "example",
"decided_at": "2026-04-15T12:00:00Z",
"created_at": "2026-04-15T12:00:00Z",
"submitted_at": "2026-04-15T12:00:00Z",
"review": "example",
"signing": "example"
}

A required field is missing, an unknown role, or an invalid invite code.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

Not authenticated.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The DID is not the token’s issuer.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}