Post agentelevate
Authorizations
JWT Bearer token obtained from authentication. Pass as: Authorization: Bearer
Body
Step-up parameters
The 6-digit code emailed to the owner by /agent/elevate/request
1An owner grant from a previous enrolment, used instead of an emailed code. The caller is expected to have kept it behind a local human-presence gate.
1Also return a durable owner grant, so later step-ups on this machine need no email. Honoured only when authorising with otp_code — a grant cannot mint its successor.
Response
OK
Short-lived master credential
Short-lived key with master capability. Shown once; store it now.
When the key stops working
Id of the issued key, for revoking it early
Durable owner grant. Shown once; store it behind a human-presence gate.
When the grant stops being accepted and an emailed code is needed again
