Interns

Sign a daemon request with the caller's identity

Signs the SHA-256 digest of one request the CLI is about to send to the intern daemon, binding it to the intern and to the signed-in member so personal connections resolve. Only an OAuth session from ori login --oidc whose grant carries vault:read can sign: an API key is refused with 403 because it names no person, and an interns-only grant is refused with 403 because a proof releases that user's personal connections. The route is behind the same gate as chat and counts against the chat turn limiter. The response is sent with Cache-Control: no-store. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as eu.openrouter.ai are refused. API key required.

post/interns/{internId}/daemon/sign

Path parameters

internIdstring required

ID of an intern visible to the authenticated API key.

Example:7c9e6679-7425-40de-944b-e07fc1f90ae7

ID of an intern visible to the authenticated API key.

Request body

bodySha256string required

Lower-case hex SHA-256 of the exact bytes the CLI will send as the daemon request body.

Example request

{
  "bodySha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}

Response

Signature headers for the digest.

x-ori-invoke-signaturestring required

Base64 Ed25519 signature over the intern id, timestamp, user and body digest.

x-ori-invoke-timestampstring required

Unix seconds at signing; the daemon refuses proofs older than its window.

x-ori-invoke-userstring required

The verified OAuth subject the proof names. Never taken from the request.

Example response

{
  "x-ori-invoke-signature": "MEUCIQ...",
  "x-ori-invoke-timestamp": "1789000000",
  "x-ori-invoke-user": "user_2abc"
}

Changes

Changed in 1 of the 339 revisions of this API.1