REST API

POST /v1/session/lock

Lock this session

POST /v1/session/lock

Ends the SDK session (best-effort server-side, always locally) and wipes its key material. Every route after this one fails until the process is restarted and re-enrolls (or restores via OpenBao) — this does not restart the session itself.

Responses #

  • 202 Successful Response

  • 401 No client certificate reached this route (`client_certificate_required`).

    • error object required

      The body of every non-2xx response: what went wrong, for a program and for a person.

  • 403 The client certificate's CN is not in `DIAGNOS_API_ALLOWED_CLIENT_CN` (`client_certificate_cn_not_allowed`).

    • error object required

      The body of every non-2xx response: what went wrong, for a program and for a person.

curl --cert client.crt --key client.key \
  -X POST "https://api.imgexam.com/v1/session/lock" \
  -H "Content-Type: application/json"
{}