`GET /v1/orgs/{org}/enrollment-tokens`.
const url = 'https://api.updawg.net/v1/orgs/example/enrollment-tokens';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.updawg.net/v1/orgs/example/enrollment-tokensParameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Organization slug.
Responses
Section titled “Responses”Every token, newest first, revoked and used-up ones included — the list is also the answer to “what could have enrolled that host”.
A token as a list shows it: everything but the value.
object
etk_…. The record, not the credential.
object
Whether an agent presenting it now would be let in: not revoked, not expired, not used up. The same three conditions the gateway checks, so the portal does not have to know them.
Hosts that enrolled with it and then checked in. A use is charged on the first check-in, not when the certificate is issued, so an attempt the agent refused costs nothing (DAWG-224).
Examplegenerated
[ { "created_at": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "id": "example", "labels": { "additionalProperty": "example" }, "max_uses": 1, "name": "example", "revoked_at": "2026-04-15T12:00:00Z", "usable": true, "uses": 1 }]No session.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Not permitted for this role.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}No such organization, or not yours — one answer for both.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.
object
Examplegenerated
{ "detail": "example", "status": 1, "title": "example", "type": "example"}