Skip to main content
POST
Issue Bluetooth OTA Grant
Requires a secret API key or a restricted key with devices:write. Call from your backend after authorizing the user’s device access; never embed that key in a mobile app. The device must belong to the key’s project and have an enrolled public key. The release must be published in the same organization, match the device model, and contain a Bluetooth image.
string
required
Backend device ID (dev_*), not the Bluetooth peripheral identifier.
string
required
Exact published release (fw_*) selected using the device-filtered release list.
Returns 201 with grant_blob (opaque base64) and expires_at (ISO timestamp). Pass the grant and the same release’s type=ufw download metadata to the App SDK. Do not log the grant or reuse it after expiry. Unknown devices, foreign releases, and unpublished releases return 404. Invalid input, an unenrolled device, a model mismatch, or a missing Bluetooth image returns 400. Missing authentication returns 401; insufficient scopes or unsupported token types return 403. Grant issuance does not schedule a network update or establish successful installation. Verify the device-reported version after reboot. See Firmware Updates for both delivery paths.