OUTCOME · Create or advance
What changes
Creates or updates private owner data as SELF_ASSERTED and potentially UNVERIFIED. It does not issue a credential or verify the value.
v2Trust & identity
/api/v2/trust/claimsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Create a new allowlisted subject claim or update an eligible existing claim after the subject confirms its exact value, validity, and credential-inclusion preference.
OUTCOME · Create or advance
Creates or updates private owner data as SELF_ASSERTED and potentially UNVERIFIED. It does not issue a credential or verify the value.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the trust:write scope.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated key reused for every retry of the same logical mutation.EXAMPLElaunch-treasury-v1-001
Content-TypeheaderRequiredapplication/jsonSigned mutations accept canonical JSON only.EXAMPLEapplication/json
Content-DigestheaderRequiredRFC 9530 SHA-256 digestDigest of the exact transmitted body bytes.EXAMPLEsha-256=:47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=:
Signature-InputheaderRequiredRFC 9421 signature parametersCovers @method, @path, content-digest, content-type, and idempotency-key; includes keyid, nonce, created, and expires.EXAMPLEsig1=("@method" "@path" "content-digest" "content-type" "idempotency-key");created=1786582800;expires=1786583100;nonce="01J…";keyid="machine-prod"
SignatureheaderRequiredEd25519 HTTP Message SignatureSignature made by an active public key registered to the authenticated client.EXAMPLEsig1=:base64-signature:
claim_idbodyOptional32-character identifierEligible owner claim to update; omit to create.EXAMPLE99999999999999999999999999999999
namespacebodyRequiredallowlisted namespacePurpose namespace accepted by Identity.EXAMPLEcontact
keybodyRequiredallowlisted claim keyStable key inside the namespace.EXAMPLEpreferred_name
labelbodyRequiredstringSubject-facing label.EXAMPLEPreferred name
value_typebodyRequiredallowlisted value typeDeclared representation used for validation.EXAMPLETEXT
valuebodyRequiredprivate typed stringSubject claim cleartext; never place documents, biometric media, screening data, or secrets here.EXAMPLEGrace
include_in_credentialbodyRequiredbooleanSubject preference for future credential inclusion; grants no issuance or disclosure authority.EXAMPLEtrue
valid_untilbodyRequiredRFC 3339 timestamp | nullOptional subject-supplied expiry; null means no claim-level expiry, not permanent verification.EXAMPLEnull
REQUEST
{
"namespace": "contact",
"key": "preferred_name",
"label": "Preferred name",
"value_type": "TEXT",
"value": "Grace",
"include_in_credential": true,
"valid_until": null
}RESPONSES
{
"claim_id": "99999999999999999999999999999999",
"namespace": "contact",
"key": "preferred_name",
"label": "Preferred name",
"value_type": "TEXT",
"value": "Grace",
"assurance_level": "SELF_ASSERTED",
"verification_status": "UNVERIFIED",
"include_in_credential": true,
"valid_from": "2026-09-01T00:00:00Z",
"valid_until": null,
"created_at": "2026-09-01T00:00:00Z",
"updated_at": "2026-09-01T00:00:00Z"
}{
"code": "invalid_trust_request",
"message": "The JSON, identifier, idempotency key, or required signed headers are malformed."
}invalid_trust_request{
"code": "invalid_credentials",
"message": "The bearer credential or HTTP Message Signature is missing, expired, replayed, or invalid."
}invalid_credentials{
"code": "insufficient_scope",
"message": "The subject lacks exact trust:write authority or the resource is ineligible."
}insufficient_scope{
"code": "trust_conflict",
"message": "The idempotency key is bound to different instructions or current lifecycle state conflicts."
}trust_conflict{
"code": "invalid_trust_request",
"message": "A policy, jurisdiction, claim field, lifecycle value, or reason is outside the published contract."
}invalid_trust_request{
"code": "identity_unavailable",
"message": "The authoritative Identity trust service is unavailable."
}identity_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗