Register the tenant
Step 2 of 3 in Onboard a tenant.
Registration takes four decisions in one request. tenant carries the display name, the slug and
initialPlatformSubdomain. contacts carries the technical contact and where the owner admin comes
from. login carries enabled and defaultAuthorizationServerRequired. provisioning carries
the capability flags: issuer and verifier create the OID4VCI and OID4VP instances and their public
endpoints, keysAndDids creates the key material those instances sign with, and sampleData seeds
lab designs. Leave sample data off for production tenants.
Keep the tenant id and the correlation id from the response. A 201 means provisioning started,
not that it finished. Follow it with the correlation id:
Provisioning runs as named steps. status reads COMPLETED only when every requested default exists;
on failure, lastError and the failing step name explain what went wrong. Until then, do not assume
issuer metadata, verifier endpoints or the default authorization server exist.
Registration errors such as REMOTE_PLATFORM_CONFIG_UNAVAILABLE or a missing internal client secret
point at deployment secrets, not at the request body.
Next
Continue with step 3, Confirm public endpoints and runtime discovery.