Enrollment tokens

Issue a one-time plaintext token for a Worker pool. The Manager stores only an HMAC hash and expiry; the plaintext is returned in the create response and cannot be retrieved later.

Issue an enrollment token

Creates a time-limited plaintext token and stores only its HMAC hash.

POST
/api/v1/operations/enrollment-tokens201

Parameters

NameInTypeDescription
poolbodycpu | nvidia | intel | amdPool the token authorizes.Default: cpu
expiresInSecondsbodyinteger (60..2592000)Token lifetime in seconds.Default: 3600
The token is single-use and returned only once. Treat the response as a secret.
Request
curl --request POST http://localhost:4400/api/v1/operations/enrollment-tokens \
  --header 'authorization: Bearer ADMIN_ACCESS_TOKEN' \
  --header 'content-type: application/json' \
  --data '{"pool":"cpu","expiresInSeconds":3600}'
Response
{
  "id": "f7cc4fb2-b4d4-4707-863f-4f1d4c216a3e",
  "token": "ef_enroll_plaintext_returned_once",
  "expiresAt": "2026-09-10T10:00:00.000Z"
}

Possible errors

400The pool or expiry is invalid.

Handling guidance

  • Deliver the plaintext through a secret manager or one-time bootstrap channel.
  • Never log the response body.
  • Keep WORKER_ENROLLMENT_TOKEN_PEPPER at least 32 characters and outside source control.
  • Prefer short expiry periods that cover only the expected enrollment window.