Apply to the authority
const url = 'https://example.com/api/v1/onboarding/apply';const options = { method: 'POST', headers: { cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E', 'Content-Type': 'application/json' }, body: '{"invite_code":"example","legal_name":"example","kvk_number":"example","contact_email":"example","requested_roles":["example"],"name":"example","color":"example","role":"example","signatory_name":"example","signatory_email":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/onboarding/apply \ --header 'Content-Type: application/json' \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E \ --data '{ "invite_code": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "name": "example", "color": "example", "role": "example", "signatory_name": "example", "signatory_email": "example" }'Sends the application, signed with the participant’s DID, to the authority, and stores the organisation’s profile. The authority e-mails the signatory the rulebook declaration and the mandate to sign.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”An application to join the dataspace.
object
Eight digits.
At least one; the roles the authority offers (/api/v1/onboarding/roles there).
Display name, colour and role of the organisation (registration wizard of a fresh connector). Optional: defaults stay in force.
Person authorised (KvK) to sign the rulebook declaration and mandate.
Example generated
{ "invite_code": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "name": "example", "color": "example", "role": "example", "signatory_name": "example", "signatory_email": "example"}Responses
Section titled “Responses”OK.
The participant’s application to the authority, and its membership.
object
Not_started | awaiting_signature | pending | approved | active | rejected | suspended
Latest signing request at the authority (state, sent/signed times, signer, document hashes).
Example generated
{ "state": "example", "application_id": "example", "submitted_at": "2026-04-15T12:00:00Z", "message": "example", "roles": [ "example" ], "signatory_name": "example", "signatory_email": "example", "signing": "example", "decided_at": "2026-04-15T12:00:00Z"}A field is missing or not valid.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Already a member.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The authority could not be reached or refused.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}