The D270 token-authenticated mint for a device that holds NO certificate yet — the pre-enrollment
failure-reporting channel (bootstrap/updater/scanner beacons). Anonymous like /enroll: the
enrollmentToken in the body is the credential, and every token failure collapses to one
indistinguishable 401 (the structured outcome is logged server-side by the validator, never
revealed). The minted URL targets the quarantined logs/<tenant>/_unverified/<logId>
key — claimed identity fields (claimedDeviceId/claimedHostname) ride the ops log line
as CLAIMS and are never joined to device rows. Bounds (Q386): the smaller
UnverifiedMaxLogSizeBytes 413 cap, the shared per-tenant rate 429, and the per-tenant daily
unverified cap 429 (the per-device quota keyed on the pseudo-device). Refusal WARNs are gated to
first-per-tenant-per-hour so a flood cannot write its own log storm.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
200Success
