Skip to content

Exchange an app assertion for an installation bearer

POST
/auth/app-installation-token
curl --request POST \
--url https://api.vampikez.fun/auth/app-installation-token \
--header 'Content-Type: application/json' \
--data '{ "assertion": "eyJhbGciOiJFZERTQSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhY21lLWNoZWNrb3V0LWJvdCIsInN1YiI6ImFjbWUtY2hlY2tvdXQtYm90IiwiYXVkIjoiaHR0cHM6Ly9hY2NvdW50LmV4YW1wbGUuY29tIiwiaWF0IjoxNzg2MTk1MDAwLCJleHAiOjE3ODYxOTUzMDB9.9tS1oQ2vKcYy8mB0dR4nZq7fXw3LhJp5A6TgEuVbNsC", "installationId": "e3f7b219-6c40-4a8e-b591-07d2c48f3a65", "resourceAudience": "wamp-cloud" }'

The assertion is an Ed25519 JWT signed by the App’s registered private key. The returned token has audience wamp-cloud, is bound to one live installation, and is never a browser credential.

Media typeapplication/json
object
assertion
required

App assertion: a short-lived (<=600s) JWT signed with the app private key. iss and sub are both the app slug, and aud MUST be the platform JWT issuer – decode iss from any token the platform has issued you. It is NOT the API origin; using the endpoint URL here fails as 401 invalid_assertion, which is indistinguishable from a bad signature.

string
>= 20 characters <= 4096 characters
installationId
required

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
resourceAudience
required

Exact registered resource-server audience requested by the caller, for example wamp-cloud. Account intersects the caller installation’s live grant with this resource before issuing the bearer.

string
>= 1 characters <= 128 characters
setupAuthorityId

Optional opaque setup authority returned by an authorized installation intent. Account binds its exact live authorizing membership into the token; the App cannot supply a membership id.

string format: uuid
Example
{
"assertion": "eyJhbGciOiJFZERTQSIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJhY21lLWNoZWNrb3V0LWJvdCIsInN1YiI6ImFjbWUtY2hlY2tvdXQtYm90IiwiYXVkIjoiaHR0cHM6Ly9hY2NvdW50LmV4YW1wbGUuY29tIiwiaWF0IjoxNzg2MTk1MDAwLCJleHAiOjE3ODYxOTUzMDB9.9tS1oQ2vKcYy8mB0dR4nZq7fXw3LhJp5A6TgEuVbNsC",
"installationId": "e3f7b219-6c40-4a8e-b591-07d2c48f3a65",
"resourceAudience": "wamp-cloud"
}

Installation token minted

Media typeapplication/json

Result of exchanging a signed App assertion for the installation-scoped bearer that every /v1 request carries.

object
success
required

Always true on this response; a refused exchange returns an HTTP error status with an error code instead

boolean
token
required

The bearer to send as Authorization: Bearer <token>, bound to the one installation and one exact resource audience named in the exchange

string
expiresIn
required

Token lifetime in seconds from issuance, currently 600; mint a new token before this elapses rather than caching it longer

integer
>= 1
Example
{
"success": true,
"token": "eyJhbGciOiJFZERTQSIsImtpZCI6ImNsb3VkLTIwMjYtMDgifQ.eyJhdWQiOiJ3YW1wLWNsb3VkIiwiaW5zdGFsbGF0aW9uSWQiOiJlM2Y3YjIxOS02YzQwLTRhOGUtYjU5MS0wN2QyYzQ4ZjNhNjUiLCJpYXQiOjE3ODYxOTUwMDIsImV4cCI6MTc4NjE5NTYwMn0.Kx7Rd0uPnJ4wLbQ9mZaE2sT6yVfHgCiO5r1XjB3NtAe",
"expiresIn": 600
}

Malformed request

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "invalid_request"
}

No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "bearer_credential_required"
}

Live installation, scope or organization policy denies the operation

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "insufficient_scope",
"requiredScope": "wamp.cloud.sessions:create"
}

The request body was never read. Either the Content-Type is not a JSON media type — bodies are parsed only under application/json and RFC 6839 application/*+json — or its content encoding or charset was refused. unsupported_media_type echoes the type you sent in mediaType. Malformed JSON under an accepted media type is a different answer: 400 malformed_request_body.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "unsupported_media_type",
"mediaType": "application/x-www-form-urlencoded"
}

The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_rate_limit_exceeded",
"retryAfterSeconds": 3
}
Retry-After
integer
>= 1
RateLimit-Policy
string

IETF HTTPAPI structured quota policy

RateLimit
string

IETF HTTPAPI structured current service limit

The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "internal_error"
}

A retryable condition: a workspace, runtime or provider that is not available yet, or service_unavailable while the service restarts for a release or its database cannot serve the request in time. Retry after the Retry-After this response carries.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_workspace_unavailable"
}
Retry-After
integer