Ga naar inhoud

The state of the application

GET
/api/v1/onboarding
curl --request GET \
--url https://example.com/api/v1/onboarding \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E

Where the application to the authority stands: not_started, awaiting_signature (the signatory has to sign the rulebook declaration and the mandate), pending (the authority checks), approved, active (the membership credential is in the wallet), rejected or suspended.

OK.

Media typeapplication/json

The participant’s application to the authority, and its membership.

object
state
required

Not_started | awaiting_signature | pending | approved | active | rejected | suspended

string
application_id
string | null
submitted_at
string | null format: date-time
message
string | null
roles
Array<string>
signatory_name
string | null
signatory_email
string | null
signing

Latest signing request at the authority (state, sent/signed times, signer, document hashes).

object | null
decided_at
string | null format: date-time

Example generated

{
"state": "example",
"application_id": "example",
"submitted_at": "2026-04-15T12:00:00Z",
"message": "example",
"roles": [
"example"
],
"signatory_name": "example",
"signatory_email": "example",
"signing": "example",
"decided_at": "2026-04-15T12:00:00Z"
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}