List applications
const url = 'https://example.com/api/v1/onboarding/applications';const options = { method: 'GET', headers: {cookie: 'bl_authority_session=<bl_authority_session>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/onboarding/applications \ --cookie bl_authority_session=<bl_authority_session>The latest 500, newest first.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
A page of a list. next_cursor is null on the last page.
object
An application as the API shows it: documents the JSON built in
[application_json].
object
Ignored with an invite: its roles count.
Person authorised to sign on behalf of the organisation (KvK).
awaiting_signature, pending, approved or rejected.
The roles asked for, or those of the invite; after approval the granted ones.
Approved only.
Why it was rejected.
The check of the reviewer: kvk_verified, verified_by, verified_at, note, signer.
The latest signing request of the signatory.
Pass as cursor for the next page.
Example generated
{ "items": [ { "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true }, "id": "example", "state": "example", "roles": [ "example" ], "granted_roles": [ "example" ], "reason": "example", "decided_by": "example", "decided_at": "2026-04-15T12:00:00Z", "created_at": "2026-04-15T12:00:00Z", "submitted_at": "2026-04-15T12:00:00Z", "review": "example", "signing": "example" } ], "next_cursor": "example"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}