Apply for membership
const url = 'https://example.com/api/v1/onboarding/applications';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"did":"example","slug":"example","name":"example","legal_name":"example","kvk_number":"example","contact_email":"example","requested_roles":["example"],"dsp_endpoint":"example","dataplane_url":"example","color":"example","invite_code":"example","signatory_name":"example","signatory_email":"example","key_storage":{"source":"example","non_exportable":true}}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/onboarding/applications \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true } }'Sent by the applicant’s connector, with a DCP token signed by the DID that applies (proof of control over the DID). The authority sends the signatory the rulebook declaration and the mandate to sign. One open application per DID: an existing one is returned.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”What an applicant’s connector declares.
object
Ignored with an invite: its roles count.
Person authorised to sign on behalf of the organisation (KvK).
Example generated
{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true }}Responses
Section titled “Responses”OK.
An application as the API shows it: documents the JSON built in
[application_json].
object
Ignored with an invite: its roles count.
Person authorised to sign on behalf of the organisation (KvK).
awaiting_signature, pending, approved or rejected.
The roles asked for, or those of the invite; after approval the granted ones.
Approved only.
Why it was rejected.
The check of the reviewer: kvk_verified, verified_by, verified_at, note, signer.
The latest signing request of the signatory.
Example generated
{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true }, "id": "example", "state": "example", "roles": [ "example" ], "granted_roles": [ "example" ], "reason": "example", "decided_by": "example", "decided_at": "2026-04-15T12:00:00Z", "created_at": "2026-04-15T12:00:00Z", "submitted_at": "2026-04-15T12:00:00Z", "review": "example", "signing": "example"}A required field is missing, an unknown role, or an invalid invite code.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Not authenticated.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The DID is not the token’s issuer.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}