Skip to main content
Submit the final operator signature for a Persona registration or DNS renewal. You must first complete Verify a Persona DNS challenge through the same Directory deployment. The verification response contains a canonical_payload that already binds the DNS attestation, operation, nonces, operator DID, constraints, and expiration. A registration payload also binds the proposed controllers and threshold. A renewal preserves the finalized controller set instead of encoding a replacement; use the controller-rotation endpoint for changes. Decode and sign the returned bytes locally. Submit the bound intent fields again so the Directory can reconstruct and compare the payload; do not alter them between verification and submission. Persona v1 requires controller_threshold to equal 1. The controller set can contain more than one authorized verification-method ID, but each current update carries one active-controller signature.

Request

string
required
Persona prepared by the verified challenge.
string
Optional body copy of the path Persona. When supplied, it must match after normalization.
string
required
Verified, unused challenge ID.
string
required
register_persona or renew_persona, exactly as verified.
string
required
Operator DID bound to the DNS challenge.
string[]
Controller set from the verified intent. Required for registration; renewal must omit it or repeat the finalized set exactly.
integer
Must equal 1 when supplied.
object
Requested constraints from the verified intent. Omit effective_ttl_seconds.
integer
required
Unix-millisecond DNS-verification expiration from the verified intent.
string
required
Operator nonce used to build the verified intent.
string
required
Authorization expiration used to build the verified intent.
string
required
Directory attestor account returned by challenge verification.
string
required
Directory attestation signature returned by challenge verification.
string
required
Exact value returned by challenge verification, encoded as 0x-prefixed hexadecimal.
string
required
Same verification-method ID declared during verification.
string
required
Ed25519 signature over the decoded canonical payload bytes, encoded as hexadecimal or Base64.

Response

202 Response
For renewal, operation is renew_persona. The finalized renewal can reactivate an expired or revoked Persona under its existing operator. 202 Accepted confirms chain submission, not finalization. Read the Persona until its revision, active, verified_at, and verification_expires_at reflect the finalized operation.

Straight to the point

  • Prerequisite: verified DNS challenge through the same Directory deployment
  • Sign: decoded canonical_payload returned by verification
  • Challenge: single-use
  • Accepted submission: 202