- Legion API
- Federation
- Renew a Legion's certificates
Renew a Legion's certificates
POST
/v3/federation/{id}/renew
const url = 'https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/federation/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/renew';const options = {method: 'POST'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/federation/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/renewIssues a fresh Nebula certificate plus refreshed NATS account material for an existing Legion. Mesh-only machines renew via /v3/mesh and 404 here. The owning org is resolved from the path parameter. Requires org:operator on that org.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”id
required
string format: uuid
Responses
Section titled “Responses”Successful response
Media typeapplication/json
object
cert_not_after
required
string
files
required
object
key
additional properties
string
hostname
required
string
initial_roster
required
Array<object>
object
cert_fingerprint
string
cert_is_expired
required
boolean
cert_not_after
required
string
enrolled_at
required
string
entity_id
string format: uuid
hostname
required
string
ip
required
string
machine_id
required
string format: uuid
organization_id
required
string format: uuid
status
required
string
ip
required
string
lighthouses
required
Array<object>
object
endpoints
required
Array<string>
ip
required
string
machine_id
required
string format: uuid
nats_url
string
Examplegenerated
{ "cert_not_after": "example", "files": { "additionalProperty": "example" }, "hostname": "example", "initial_roster": [ { "cert_fingerprint": "example", "cert_is_expired": true, "cert_not_after": "example", "enrolled_at": "example", "entity_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "hostname": "example", "ip": "example", "machine_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "organization_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "status": "example" } ], "ip": "example", "lighthouses": [ { "endpoints": [ "example" ], "ip": "example" } ], "machine_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "nats_url": "example"}Bad Request
Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{ "code": 400, "details": [ { "Field": "organization_id", "Issue": "must be a valid UUID format" } ], "message": "Request cannot be processed due to invalid input", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Unauthorized
Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{ "code": 401, "details": [ { "Field": "authorization_header", "Issue": "Bearer token is expired or malformed" } ], "message": "Authentication credentials are missing or invalid", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Forbidden
Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{ "code": 403, "details": [ { "Field": "required_scope", "Issue": "requires 'orion:settings:write' scope, but token only has 'orion:settings:read'" } ], "message": "Access denied: insufficient permissions for this resource", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Not Found
Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{ "code": 404, "details": [ { "Field": "organization_id", "Issue": "organization with ID 'a1b2c3d4-e5f6-7890-abcd-ef1234567890' not found" } ], "message": "The requested resource could not be found", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Internal Server Error
Media typeapplication/json
object
category
required
The category of the error
string
code
required
The HTTP status code
number
details
Additional details about the error
Array<object>
object
field
The field that caused the error
string
issue
The specific issue with the field
string
message
required
A human-readable error message
string
status
required
The status of the response, always ‘error’ for error responses
string
timestamp
required
The timestamp when the error occurred
string format: date-time
trace_id
required
A unique identifier for tracing the error
string format: uuid
Example
{ "category": "server_error", "code": 500, "details": [ { "field": "field_name", "issue": "Field validation issue" } ], "message": "Internal Server Error", "status": "error", "timestamp": "2024-03-15T10:30:00Z", "trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"}Version 3.14.0 · commit 0771262
