- Legion API
- Mesh
- Renew a mesh-only machine's certificate
Renew a mesh-only machine's certificate
const url = 'https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/mesh/machines/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/renew';const options = {method: 'POST'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/mesh/machines/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/renewIssues a fresh short-lived Nebula certificate for a mesh-only machine. Requires system admin, but system admin access alone is insufficient: only the identity that joined the machine may renew it, and any other caller (including another system admin) receives 403. Legion machines renew via /v3/federation and 404 here.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Responses
Section titled “Responses”Successful response
object
object
object
Examplegenerated
{ "cert_not_after": "example", "files": { "additionalProperty": "example" }, "hostname": "example", "ip": "example", "lighthouses": [ { "endpoints": [ "example" ], "ip": "example" } ], "machine_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"}Bad Request
object
object
Example
{ "code": 400, "details": [ { "Field": "organization_id", "Issue": "must be a valid UUID format" } ], "message": "Request cannot be processed due to invalid input", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Unauthorized
object
object
Example
{ "code": 401, "details": [ { "Field": "authorization_header", "Issue": "Bearer token is expired or malformed" } ], "message": "Authentication credentials are missing or invalid", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Forbidden
object
object
Example
{ "code": 403, "details": [ { "Field": "required_scope", "Issue": "requires 'orion:settings:write' scope, but token only has 'orion:settings:read'" } ], "message": "Access denied: insufficient permissions for this resource", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Not Found
object
object
Example
{ "code": 404, "details": [ { "Field": "organization_id", "Issue": "organization with ID 'a1b2c3d4-e5f6-7890-abcd-ef1234567890' not found" } ], "message": "The requested resource could not be found", "status": "error", "timestamp": "2026-01-15T14:32:45Z", "trace_id": "req_2J9K8L7M6N5P4Q3R"}Internal Server Error
object
The category of the error
The HTTP status code
Additional details about the error
object
The field that caused the error
The specific issue with the field
A human-readable error message
The status of the response, always ‘error’ for error responses
The timestamp when the error occurred
A unique identifier for tracing the error
Example
{ "category": "server_error", "code": 500, "details": [ { "field": "field_name", "issue": "Field validation issue" } ], "message": "Internal Server Error", "status": "error", "timestamp": "2024-03-15T10:30:00Z", "trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"}Version 3.14.0 · commit 0771262
