Sign a daemon request with the caller's identity
Signs the SHA-256 digest of one request the CLI is about to send to the intern daemon, binding it to the intern and to the signed-in member so personal connections resolve. Only an OAuth session from ori login --oidc whose grant carries vault:read can sign: an API key is refused with 403 because it names no person, and an interns-only grant is refused with 403 because a proof releases that user's personal connections. The route is behind the same gate as chat and counts against the chat turn limiter. The response is sent with Cache-Control: no-store. The API key selects the caller, workspace and visible interns. An intern's own API key sees only that intern: the collection and every other intern answer 404 to it. There is no default workspace fallback. Requests on regional hostnames such as eu.openrouter.ai are refused. API key required.
Path parameters
ID of an intern visible to the authenticated API key.
ID of an intern visible to the authenticated API key.
Request body
Example request
{
"bodySha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}Response
Signature headers for the digest.
Example response
{
"x-ori-invoke-signature": "MEUCIQ...",
"x-ori-invoke-timestamp": "1789000000",
"x-ori-invoke-user": "user_2abc"
}Changes
Changed in 1 of the 339 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○