Download OpenAPI specification:Download
Enroll and manage endpoint devices — the headless Cortega Endpoint Guard service and the AI Verifier desktop app — from your own provisioning, MDM, or asset-management system instead of the console, one device at a time.
A tenant admin issues an API key under System → API Access; the key
is a bearer token prefixed crt_ and is shown once at creation. (Distinct
from the gateway's ck_ virtual key.)
Authorization: Bearer crt_...
Every response carries X-RateLimit-Limit / X-RateLimit-Remaining /
X-RateLimit-Reset; a 429 includes Retry-After (seconds).
The key's tenant is resolved from the key itself — never from a request parameter — so a key can only ever act on its own tenant's devices and CAs.
| Scope | Grants |
|---|---|
edge:read |
list enrollment CAs and enrolled devices |
edge:write |
everything in edge:read, plus create/disable CAs, mint client certificates, create invitations, and deprovision devices |
These same endpoints also accept a console session, so the two callers
stay in sync. The edge feature must be included in the install license.
Headless Endpoint Guard — client certificates. Create one enrollment CA
(POST /edge/enrollment/cas), then call POST /edge/enrollment/cas/{id}/client-certs once per device from your
provisioning system. Drop the returned identity_pem on the machine along
with the Cortega address; on startup the service presents the certificate
and registers itself — no console step per device.
AI Verifier — invitations. The desktop app is tied to a person, so it
cannot be enrolled by an admin credential alone. Call POST /edge/sso/invitations once per user to mint an invitation link, distribute
the links, and each user finishes with SSO in their browser. (Domain-matched
SSO — configured per tenant — needs no API call at all.)
Use GET /edge/agents to reconcile what is enrolled and DELETE /edge/agents/{id} to deprovision.
A trusted enrollment authority. Cortega resolves a device's tenant from the CA that signed its client certificate.
curl -H "Authorization: Bearer $CORTEGA_API_KEY" \ "https://$CORTEGA_HOST/api/v1/edge/enrollment/cas"
[- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "mode": "generated",
- "ca_cert_pem": "string",
- "trust_enabled": true,
- "has_private_key": true,
- "subject_policy": { },
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
]Either import your own CA certificate (ca_cert_pem; Cortega never sees the private key — requires the MDM device-auth feature) or have Cortega generate one (generate_cortega_ca: true — requires the Cert Manager feature). Requires edge:write.
| name required | string |
| generate_cortega_ca | boolean Have Cortega generate the CA and keep the key. Mutually exclusive with |
| ca_cert_pem | string Your CA certificate, PEM. Cortega never receives the private key. |
object Optional constraints on the certificates this CA may mint. |
{- "name": "string",
- "generate_cortega_ca": true,
- "ca_cert_pem": "string",
- "subject_policy": { }
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "mode": "generated",
- "ca_cert_pem": "string",
- "trust_enabled": true,
- "has_private_key": true,
- "subject_policy": { },
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}A disabled CA stops validating new devices and cannot mint certificates. Requires edge:write.
| id required | string <uuid> The enrollment CA's id. |
| trust_enabled required | boolean |
{- "trust_enabled": true
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "mode": "generated",
- "ca_cert_pem": "string",
- "trust_enabled": true,
- "has_private_key": true,
- "subject_policy": { },
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}The bulk-enrollment primitive: call once per device. The CA must be enabled and must have a private key (a generated CA, or an imported CA whose key you also uploaded). Requires edge:write.
| id required | string <uuid> The enrollment CA's id. |
| device_id required | string Your stable identifier for the machine. Embedded in the certificate. |
| email required | string <email> The user the device belongs to. Embedded in the certificate. |
| name | string Optional human label (e.g. the asset name). |
| valid_days | integer <= 1095 Default: 365 |
{- "device_id": "string",
- "name": "string",
- "valid_days": 365
}{- "device_id": "string",
- "cert_pem": "string",
- "key_pem": "string",
- "ca_bundle_pem": "string",
- "identity_pem": "string",
- "expires_at": "2019-08-24T14:15:22Z",
- "fingerprint_sha256": "string"
}Mints a single-use link carrying the Cortega address, the tenant, and the expected email. The user pastes it into the app's Enterprise Sign in tab and completes SSO. Requires edge:write and the edge SSO feature.
| email required | string <email> |
| cortega_base_url required | string The base URL the device should reach Cortega at (e.g. https://cortega.company.internal). |
{- "cortega_base_url": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "cortega_base_url": "string",
- "invite_url": "string",
- "code": "string",
- "created_at": "2019-08-24T14:15:22Z"
}Invalidates the old link and returns a new one. Requires edge:write.
| id required | string |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",
- "cortega_base_url": "string",
- "invite_url": "string",
- "code": "string",
- "created_at": "2019-08-24T14:15:22Z"
}curl -H "Authorization: Bearer $CORTEGA_API_KEY" \ "https://$CORTEGA_HOST/api/v1/edge/agents"
[- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "device_id": "string",
- "hostname": "string",
- "serial_number": "string",
- "platform": "string",
- "agent_version": "string",
- "active_clients": [
- "string"
], - "identity_method": "unknown",
- "enrollment_ca_id": "a76665ba-f340-4487-ba22-94c476a1de8b",
- "enrollment_ca_name": "string",
- "client_cert_fingerprint": "string",
- "ca_trusted": true,
- "tls_interception_enabled": true,
- "system_proxy_enabled": true,
- "last_ip": "string",
- "registered_at": "2019-08-24T14:15:22Z",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0"
}
]Requires edge:read.
| id required | string <uuid> The device record's id (the |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "device_id": "string",
- "hostname": "string",
- "serial_number": "string",
- "platform": "string",
- "agent_version": "string",
- "active_clients": [
- "string"
], - "identity_method": "unknown",
- "enrollment_ca_id": "a76665ba-f340-4487-ba22-94c476a1de8b",
- "enrollment_ca_name": "string",
- "client_cert_fingerprint": "string",
- "ca_trusted": true,
- "tls_interception_enabled": true,
- "system_proxy_enabled": true,
- "last_ip": "string",
- "registered_at": "2019-08-24T14:15:22Z",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0"
}Removes the device record. A device enrolled by client certificate can re-enroll unless you also disable or narrow its CA. Requires edge:write.
| id required | string <uuid> The device record's id (the |