Most members register nothing Warden can compare, and your system may not know where they sell either. An invitation lets a member add it themselves.
POST /api/v1/integration/enrollments
Authorization: Bearer wik_...
Content-Type: application/json
{ "external_id": "member-1001", "days": 30 }{
"external_id": "member-1001",
"token": "wen_9c2e...64 hexadecimal characters",
"expires_at": "2026-10-21T18:04:11.123456+00:00",
"enroll_url": "https://3dwarden.com/enroll#wen_9c2e..."
}days is a whole number from 1 to 90 and defaults to 30. Any other field is refused. A member
your key's provider does not hold is 404.
Send the link yourself
Send enroll_url to that member from your own system. Warden does not deliver it for you.
The secret is in this response once, and Warden keeps only a hash of it. It travels after # in
the address, which a browser never sends to a server, so it reaches no access log and no referrer.
Issuing again for the same member stops the earlier invitation.
What the member sees
Your organization's name, the name on their credential, and what they have added. They can add up
to 20 shops, profiles or websites of their own, of the kinds Warden can compare (the identity
kinds in Dry run), and withdraw what they added. Nothing else about the
relationship is visible to them.
What they add is stored as registered and is never replaced by your reconcile. A sync removes
only the identities it sent.
What an invitation is not
An invitation is not a public verification id and cannot be exchanged for one in either direction. Do not print an enrollment address on a certificate.