The state of the application
const url = 'https://example.com/api/v1/onboarding';const options = { method: 'GET', headers: {cookie: 'bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/v1/onboarding \ --cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3EWhere the application to the authority stands: not_started, awaiting_signature (the signatory has to sign the rulebook declaration and the mandate), pending (the authority checks), approved, active (the membership credential is in the wallet), rejected or suspended.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”OK.
The participant’s application to the authority, and its membership.
object
Not_started | awaiting_signature | pending | approved | active | rejected | suspended
Latest signing request at the authority (state, sent/signed times, signer, document hashes).
Example generated
{ "state": "example", "application_id": "example", "submitted_at": "2026-04-15T12:00:00Z", "message": "example", "roles": [ "example" ], "signatory_name": "example", "signatory_email": "example", "signing": "example", "decided_at": "2026-04-15T12:00:00Z"}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}