Skip to main content
POST
Error

Authorizations

x-partner-access-token
string
header
required

The holder's AIR Kit partner access token, from airService.getAccessToken(). Send it with x-partner-id.

x-partner-jwt
string
header
required

JWT signed with your partner login key (the same key used for the AIR Kit login partnerJwt). Its partnerId must match x-partner-id and the AIR Kit session. Omit email unless it is this holder's. Body partnerJwt is accepted as a fallback.

Headers

x-partner-id
string<uuid>
required

Your Partner ID (UUID) from the Developer Dashboard.

Body

application/json
scope
string
required

Space-delimited scopes. openid is added automatically. Allowed: credentials.read, credentials.verify, commerce.checkout. Partner bind cannot include wallet.sign.

Example:

"credentials.read credentials.verify"

nickname
string

Display name (letters, numbers, spaces, hyphens, colons; maximum 32 characters). Defaults to Agent YYYY-MM-dd HH:mm:ss (UTC).

Maximum string length: 32
Example:

"Shopping agent"

publicKey
string

secp256r1 (P-256) public key, PEM or base64 DER. Required only when the agent will create sessions with signedMessage.

Example:

"-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE…\n-----END PUBLIC KEY-----\n"

Response

Agent bound. agentApiKey is returned only this once.

id
string<uuid>
required
createdAt
string<date-time>
required
scope
string
required

Space-delimited scopes granted to the key, including openid.

Example:

"openid credentials.read credentials.verify"

agentApiKey
string
required

Opaque secret with the prefix air_ag_. Returned only once.

Example:

"air_ag_<secret>"

publicKey
string | null

Masked PEM when a public key was bound; null for API-key-only agents.

nickname
string | null
partnerId
string<uuid> | null