> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hq.zone/llms.txt
> Use this file to discover all available pages before exploring further.

# Enroll a connector

> Completes connector enrollment: the connector agent presents its one-time enrollment
token and a PEM-encoded certificate signing request, and receives a CA-signed client
certificate, the CA certificate, and the tunnel address it should dial. This endpoint
is public and authenticated only by the one-time token (the agent has no session); the
token is single-use and time-limited. Returns 403 when the token is missing, invalid,
expired, or already redeemed.



## OpenAPI

````yaml POST /v1/mcp/connectors/enroll
openapi: 3.1.0
info:
  title: HQ API
  description: >-
    Public HTTP API for HQ. Authenticate with a Personal Access Token
    (`Authorization: Bearer hq_pat_...`) for server-side integrations, or an
    OAuth 2.1 authorization-code + PKCE flow for browser apps acting on a user's
    behalf. Both grant from the same resource:action scope vocabulary; an
    endpoint's required scope is listed under its `security`.
  license:
    name: Apache-2.0
    identifier: Apache-2.0
  version: 1.0.0
servers:
  - url: https://api.hq.zone
    description: HQ API (production)
security: []
tags:
  - name: me
    description: The signed-in user's own account
  - name: conversations
    description: Conversations and their messages
  - name: documents
    description: The content-addressed documents library
  - name: schedules
    description: Scheduled prompts and recurring tasks
  - name: agents
    description: Agents, their skills and integrations
  - name: memory
    description: What the assistant remembers (L5 governance)
  - name: tokens
    description: Personal Access Token management
  - name: billing
    description: Usage and billing
  - name: notifications
    description: In-app notification center
  - name: admin
    description: Workspace administration
  - name: integrations
    description: Workspace integrations (Slack, MCP, skills)
  - name: onboarding
    description: New-workspace onboarding wizard
  - name: auth
    description: Sign-in, sessions, and OAuth
paths:
  /v1/mcp/connectors/enroll:
    post:
      tags:
        - integrations
      summary: Enroll a connector
      description: >-
        Completes connector enrollment: the connector agent presents its
        one-time enrollment

        token and a PEM-encoded certificate signing request, and receives a
        CA-signed client

        certificate, the CA certificate, and the tunnel address it should dial.
        This endpoint

        is public and authenticated only by the one-time token (the agent has no
        session); the

        token is single-use and time-limited. Returns 403 when the token is
        missing, invalid,

        expired, or already redeemed.
      operationId: connector_enroll
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectorEnrollReq'
        required: true
      responses:
        '200':
          description: The signed client cert + CA + tunnel address
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectorEnrollResp'
        '403':
          description: Invalid, expired, or already-used enrollment token
components:
  schemas:
    ConnectorEnrollReq:
      type: object
      required:
        - token
        - csr_pem
      properties:
        csr_pem:
          type: string
        token:
          type: string
    ConnectorEnrollResp:
      type: object
      required:
        - connector_id
        - cert_pem
        - ca_pem
        - tunnel_addr
        - tunnel_server_name
      properties:
        ca_pem:
          type: string
        cert_pem:
          type: string
        connector_id:
          type: string
          format: uuid
        tunnel_addr:
          type: string
        tunnel_server_name:
          type: string

````