Manually add a federation peer
POST /admin/federation/peers
Manual peer entry — the operator pastes the peer’s instance URL + display name + the PEM-encoded Ed25519 instance public key (out-of-band coordination between operators). The automated handshake protocol lands in 1.22.B-b and uses the same row shape.
Authorizations
Section titled “Authorizations ”Request Body required
Section titled “Request Body required ”object
Must be https://, no trailing slash, no path component.
PEM-wrapped Ed25519 public key. Validated server-side.
Responses
Section titled “ Responses ”Peer created.
One row from the federation_peers registry (Phase 1.22.B-a + ADR 0043 §“Trust model”). Pairing alone shares no content — see federation_shares (1.22.C) for the access-control layer.
object
Https://peer.example (no trailing slash, no path)
PEM-wrapped Ed25519 public key (RFC 8410). May be the
placeholder string PENDING-HANDSHAKE-RESPONSE while
status is pending_outbound — the peer’s real key
replaces it when the confirm envelope arrives.
Handshake state machine (migration 00052 + v1.md §11). Outbound delivery (1.22.D) gates on connected only.
Per-peer opt-in for peer-of-peer discovery (Phase 1.22.B-d). When true, this peer appears in GET /federation/peers/visible — other peers can then surface it as a discovery suggestion. Default false; explicit opt-in.
Malformed request
object
Human-readable error summary
Example
the request could not be completedAuthentication required, missing, or invalid
object
Human-readable error summary
Example
the request could not be completedExample
{ "error": "authentication required: sign in and retry with a valid session or API token"}Authenticated but missing required capabilities
object
Human-readable error summary
Example
the request could not be completedPeer with this instance_url already exists.
object
Human-readable error summary
Example
the request could not be completed