Skip to main content
POST
POST /v1/verify/chip/challenge

Endpoint

Step 1 of chip verification. Issues a single-use challenge for one machine: a 32-byte nonce, the machine’s DID, its current DID controller, the chain ID and an expiry at most five minutes out. The machine’s chip and its DID controller sign over this challenge, and POST /v1/verify/chip/evidence consumes it. Issuing a challenge does not check a chip, set a status or record an attestation. The route takes no certificate or signature.
The route requires peaq’s onboarding token (Authorization: Bearer <token>). Without a valid token every request answers 401 ONBOARDING_AUTH_REQUIRED, before the body is read. Machine operators receive the challenge from peaq’s onboarding service; they do not hold the token.

Headers

Request body

string
required
Decimal machine ID as a string, 1 to 2^256-1, no sign, whitespace or leading zeros. A JSON number, a DID or an address returns 400 INVALID_REQUEST.
The body is a closed object with exactly this one field and at most 1024 bytes. Duplicate keys and extra fields return 400 INVALID_REQUEST. The server resolves the DID, controller and chain ID itself and generates the nonce and expiry.

Response

201 Created, Content-Type: application/json; charset=utf-8, Cache-Control: no-store. The challenge is single use. The DID controller in the challenge must still be the machine’s controller when the evidence is submitted; a change in between gets the evidence rejected.

Error responses

Errors use the coded envelope:
Branch on code, never on message. Errors never echo the token, the nonce or the request body.

Example

Illustrative response. 123 is a placeholder machine ID.