OUTCOME · Create or advance
What changes
Creates or advances only the network enrollment intent resource described by this contract after authorization, validation, policy, and idempotency gates pass.
MPC wallet lifecycle
/api/v2/wallets/enrollmentsPurpose and usage
Create one idempotent owner- and workspace-bound enrollment intent on an explicit Hybrid network while keeping customer authorization, 7-of-13 DKG, and activation separate.
When to use it
Call this when a wallet, treasury, custody, or governed agent workflow needs to apply the documented network enrollment intent transition after re-reading the current authoritative state so it can make a custody decision inside the correct owner, workspace, network, and policy boundary.
OUTCOME · Create or advance
Creates or advances only the network enrollment intent resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
The authenticated owner, workspace, network, and wallet policy remain authoritative. A wallet record, policy result, approval, ceremony, or balance never grants another lifecycle stage and cannot substitute for threshold signing or separately owned funding, settlement, publisher, matching, or trading authority.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
Use the deployed OpenAPI for exact parameters, schemas and security requirements. The tables below provide integration guidance.
Open this operation in OpenAPIRequest and response
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing wallets:write authority.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated stable key reused for retries of the same logical mutation.EXAMPLEpost-api-v2-wallets-enrollments-request-001
X-Request-IDheaderOptionalstringOptional caller correlation identifier. The gateway emits the effective value on the response.
Content-DigestheaderRequiredstringRFC 9530 sha-256 digest of the exact transmitted request-body bytes.
Signature-InputheaderRequiredstringRFC 9421 sig1 input covering @method, @path, content-digest, content-type, and idempotency-key, with created, expires, nonce, keyid, and alg=ed25519.
SignatureheaderRequiredstringRFC 9421 sig1 Ed25519 signature made by an active key registered to the bearer client.
acknowledge_activation_is_separatebodyOptionalbooleanRequired true only for Mainnet to acknowledge that enrollment does not activate deposits or withdrawals.EXAMPLEfalse
acknowledge_distributed_custodybodyOptionalbooleanRequired true only for Mainnet to acknowledge the separate 7-of-13 distributed-custody ceremony.EXAMPLEfalse
network_idbodyRequiredHybrid control-plane network identifierExact network: hybrid-devnet, hybrid-testnet, or hybrid-mainnet. It is never inferred from an asset or prior enrollment.EXAMPLEhybrid-devnet
REQUEST
{
"acknowledge_activation_is_separate": true,
"acknowledge_distributed_custody": true,
"network_id": "hybrid-devnet"
}RESPONSES
"example-value"{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentials{
"code": "invalid_credentials",
"message": "the supplied Hybrid credential is invalid"
}invalid_credentialsOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-10-02T23:27:55.510Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation Return to the V2 directory