Skip to main content
POST
The box posts a TPM attestation (PCR-7 quote) so the control plane can record its boot measurement. Device-token authenticated (Authorization: Bearer <device_token>). Control-plane verification of the quote is beta — the record is stored regardless.
Self-hosted only. See the security model for how the TPM seals the region’s keys to the hardware.