Skip to content

Renew a Legion's certificates

POST
/v3/federation/{id}/renew
curl --request POST \
--url https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/federation/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/renew

Issues a fresh Nebula certificate plus refreshed NATS account material for an existing Legion. Mesh-only machines renew via /v3/mesh and 404 here. The owning org is resolved from the path parameter. Requires org:operator on that org.

id
required
string format: uuid

Successful response

Media typeapplication/json
object
cert_not_after
required
string
files
required
object
key
additional properties
string
hostname
required
string
initial_roster
required
Array<object>
object
cert_fingerprint
string
cert_is_expired
required
boolean
cert_not_after
required
string
enrolled_at
required
string
entity_id
string format: uuid
hostname
required
string
ip
required
string
machine_id
required
string format: uuid
organization_id
required
string format: uuid
status
required
string
ip
required
string
lighthouses
required
Array<object>
object
endpoints
required
Array<string>
ip
required
string
machine_id
required
string format: uuid
nats_url
string
Examplegenerated
{
"cert_not_after": "example",
"files": {
"additionalProperty": "example"
},
"hostname": "example",
"initial_roster": [
{
"cert_fingerprint": "example",
"cert_is_expired": true,
"cert_not_after": "example",
"enrolled_at": "example",
"entity_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"hostname": "example",
"ip": "example",
"machine_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"organization_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"status": "example"
}
],
"ip": "example",
"lighthouses": [
{
"endpoints": [
"example"
],
"ip": "example"
}
],
"machine_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"nats_url": "example"
}

Bad Request

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 400,
"details": [
{
"Field": "organization_id",
"Issue": "must be a valid UUID format"
}
],
"message": "Request cannot be processed due to invalid input",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Unauthorized

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 401,
"details": [
{
"Field": "authorization_header",
"Issue": "Bearer token is expired or malformed"
}
],
"message": "Authentication credentials are missing or invalid",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Forbidden

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 403,
"details": [
{
"Field": "required_scope",
"Issue": "requires 'orion:settings:write' scope, but token only has 'orion:settings:read'"
}
],
"message": "Access denied: insufficient permissions for this resource",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Not Found

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 404,
"details": [
{
"Field": "organization_id",
"Issue": "organization with ID 'a1b2c3d4-e5f6-7890-abcd-ef1234567890' not found"
}
],
"message": "The requested resource could not be found",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Internal Server Error

Media typeapplication/json
object
category
required

The category of the error

string
code
required

The HTTP status code

number
details

Additional details about the error

Array<object>
object
field

The field that caused the error

string
issue

The specific issue with the field

string
message
required

A human-readable error message

string
status
required

The status of the response, always ‘error’ for error responses

string
timestamp
required

The timestamp when the error occurred

string format: date-time
trace_id
required

A unique identifier for tracing the error

string format: uuid
Example
{
"category": "server_error",
"code": 500,
"details": [
{
"field": "field_name",
"issue": "Field validation issue"
}
],
"message": "Internal Server Error",
"status": "error",
"timestamp": "2024-03-15T10:30:00Z",
"trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"
}

Version 3.14.0 · commit 0771262