Skip to main content
After publishing the transfer TXT record, submit the complete unsigned transfer intent. The Directory validates it against finalized state, verifies DNS, and returns an attested acceptance_payload for the new operator to sign. This step does not transfer the Persona. Decode and sign the exact acceptance_payload bytes; do not sign the hexadecimal characters or reconstruct the payload locally.

Request

string
required
Canonical Persona being transferred.
string
required
Transfer challenge ID.
string
required
Operator DID currently registered for the Persona.
string
required
Active DID accepting the Persona.
string[]
required
One through eight unique signing-key IDs published by new_operator_did.
integer
required
Must equal 1 in Persona v1.
string
required
Key that will sign acceptance_payload. It must be one of new_controller_keys.
string
required
Must be transfer_persona.
string
required
Current operator nonce returned with the challenge.
string
required
Short-lived Unix-millisecond or ISO-8601 expiration for the transfer authorization.
string
required
Active current Persona controller that will sign the final transfer payload.
object
New Persona delivery constraints. Omit effective_ttl_seconds. If omitted, the transferred Persona has no Persona-specific constraints.
integer
required
Unix-millisecond expiration for the renewed DNS verification. It must be in the future and cannot be more than 90 days away.
persona and challenge_id may also be repeated in the body. When supplied, they must match the path.

Response

200 Response
The new operator signs the decoded acceptance_payload with new_operator_signer_key_id, then sends that signature and the exact echoed verification_expires_at to the prepare endpoint.

Straight to the point

  • Verifies the fresh Persona TXT record
  • Validates both DIDs, both controller roles, constraints, nonces, and expiration
  • Returns the payload the new operator must sign
  • Does not consume the challenge or submit the transfer