StaticinitiateAssigns a node ID to the device's MAC address.
POST /v1/claim/initiate — 201 for a new reservation, 200 when one already
existed, returning the same node ID either way. That idempotency is what lets
a factory-erased device come back as the same node.
Device MAC, normalized before sending
The device's claim-start payload, forwarded whole
Correlation id for this claim attempt
The assigned node ID and any attestation challenge
StaticnormalizeStaticnormalizeReduces a broker endpoint to the bare host the device stores. The device
keeps host and port separately, so a scheme, path or :port would be
persisted verbatim into the factory partition and fail to resolve.
Broker endpoint in any form
Host only, or "" when nothing usable remains
StaticverifyExchanges the device's CSR for a signed certificate.
POST /v1/claim/verify — the CSR's subject is ignored; the certificate's
Common Name comes from the reservation. Called again after a factory erase, it
issues a new certificate and deactivates the previous one, node ID unchanged.
Same device MAC as initiate
The device's claim payload, forwarded whole
OptionalclaimCapability: CAMERA_CLAIMOptional capability, mapped to extra IoT policies
Correlation id for this claim attempt
The claim response, with mqtt_host resolved for the device
Assisted-claiming cloud calls.
Both routes live on the deployment's main API and are IAM-authorized like their neighbours, so they go through ESPSigV4APIManager and are SigV4-signed against
baseUrl. A Cognito JWT is rejected there with403 Invalid key=value pair (missing equal-sign) in Authorization header.Both calls are independently retryable: initiate is idempotent per device and caller, and verify replaces the device's certificate rather than duplicating the node.