Enrollment tokens
Issue a one-time plaintext token for a Worker pool. The Manager stores only an HMAC hash and expiry; the plaintext is returned in the create response and cannot be retrieved later.
Issue an enrollment token
Creates a time-limited plaintext token and stores only its HMAC hash.
/api/v1/operations/enrollment-tokens201Parameters
| Name | In | Type | Description |
|---|---|---|---|
pool | body | cpu | nvidia | intel | amd | Pool the token authorizes.Default: cpu |
expiresInSeconds | body | integer (60..2592000) | Token lifetime in seconds.Default: 3600 |
The token is single-use and returned only once. Treat the response as a secret.
Request
curl --request POST http://localhost:4400/api/v1/operations/enrollment-tokens \
--header 'authorization: Bearer ADMIN_ACCESS_TOKEN' \
--header 'content-type: application/json' \
--data '{"pool":"cpu","expiresInSeconds":3600}' Response
{
"id": "f7cc4fb2-b4d4-4707-863f-4f1d4c216a3e",
"token": "ef_enroll_plaintext_returned_once",
"expiresAt": "2026-09-10T10:00:00.000Z"
}Possible errors
400The pool or expiry is invalid.Handling guidance
- Deliver the plaintext through a secret manager or one-time bootstrap channel.
- Never log the response body.
- Keep
WORKER_ENROLLMENT_TOKEN_PEPPERat least 32 characters and outside source control. - Prefer short expiry periods that cover only the expected enrollment window.