CAIN-42 CAIN Studio

API reference · CAIN Identity

Issue Passport

POST /fabric/identity/passport/issue

Last reviewed 2026-10-06

POST /fabric/identity/passport/issue

ISSUE a signed passport for an identity in the caller's tenant. Agent keys are refused.

Parameters

NameInTypeMeaning
tenantquerystring or null

Request body

PassportIssueRequest (required)

FieldTypeMeaning
identity_id requiredstring
posture requiredobjectmodel/runtime/system_prompt_digest/memory_digest/tools
capabilities requiredarray of stringExplicit capabilities; each must be held by the identity now
authority_scopeobjecttargets/environments/purposes/max_risk/params
policy_referencestringdefault ""
risk_profilestringdefault "UNASSESSED"
ttl_secondsintegerdefault 3600

Responses

StatusMeaningBody
200Successful Responseobject
422Validation ErrorHTTPValidationError
401No key, or a key that is not validJSON detail
429Rate limit for your plan reached; retry after the Retry-After secondsJSON detail

Try it

This call changes data in the account the key belongs to.

The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.

Code

curl -sS -X POST 'https://cainstudio.online/fabric/identity/passport/issue' \
  -H "X-API-Key: $CAIN_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"identity_id": "identity-id", "posture": {}, "capabilities": ["capabilities"], "policy_reference": "", "risk_profile": "UNASSESSED", "ttl_seconds": 3600}'

Schemas used

HTTPValidationError · PassportIssueRequest · ValidationError

← Passport Check Action · all 30 CAIN Identity calls · Passport Issuer →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem