> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bota.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue Bluetooth OTA Grant

> Authorize an App SDK firmware transfer to an enrolled device

Requires a secret API key or a restricted key with `devices:write`. Call from
your backend after authorizing the user's device access; never embed that key
in a mobile app. The device must belong to the key's project and have an enrolled
public key. The release must be published in the same organization, match the
device model, and contain a Bluetooth image.

<ParamField path="id" type="string" required>
  Backend device ID (`dev_*`), not the Bluetooth peripheral identifier.
</ParamField>

<ParamField body="firmware_release_id" type="string" required>
  Exact published release (`fw_*`) selected using the device-filtered release list.
</ParamField>

```bash theme={null}
curl -X POST https://api.bota.dev/v1/devices/dev_abc123/ota-grant \
  -H "Authorization: Bearer sk_test_..." \
  -H "Content-Type: application/json" \
  -d '{"firmware_release_id":"fw_abc123"}'
```

Returns `201` with `grant_blob` (opaque base64) and `expires_at` (ISO timestamp).
Pass the grant and the same release's `type=ufw` download metadata to the App SDK.
Do not log the grant or reuse it after expiry.

Unknown devices, foreign releases, and unpublished releases return `404`.
Invalid input, an unenrolled device, a model mismatch, or a missing Bluetooth
image returns `400`. Missing authentication returns `401`; insufficient scopes
or unsupported token types return `403`.

Grant issuance does not schedule a network update or establish successful
installation. Verify the device-reported version after reboot. See
[Firmware Updates](/guides/firmware-updates) for both delivery paths.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.