Get an application
const url = 'https://example.com/api/v1/onboarding/applications/example';const options = { method: 'GET', headers: {cookie: 'bl_authority_session=<bl_authority_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/onboarding/applications/example \ --cookie bl_authority_session=<bl_authority_session>For users of the authority, and for the applicant’s connector with a DCP token of the DID that applied.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The id of the application.
Responses
Section titled “Responses”OK.
An application as the API shows it: documents the JSON built in
[application_json].
object
Ignored with an invite: its roles count.
Person authorised to sign on behalf of the organisation (KvK).
awaiting_signature, pending, approved or rejected.
The roles asked for, or those of the invite; after approval the granted ones.
Approved only.
Why it was rejected.
The check of the reviewer: kvk_verified, verified_by, verified_at, note, signer.
The latest signing request of the signatory.
Example generated
{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true }, "id": "example", "state": "example", "roles": [ "example" ], "granted_roles": [ "example" ], "reason": "example", "decided_by": "example", "decided_at": "2026-04-15T12:00:00Z", "created_at": "2026-04-15T12:00:00Z", "submitted_at": "2026-04-15T12:00:00Z", "review": "example", "signing": "example"}Not authenticated.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Not found.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}