Replace trust anchor
Replace the active Apple Root CA trust anchor Guardian verifies payment payloads against. The instance ships with Apple’s current root CA seeded, so you only need this if Apple rotates its root certificate. The previous anchor is superseded atomically.
A PEM that cannot be decoded as a valid X.509 certificate returns 422 with the classifier APPLE_PAY_INVALID_TRUST_ANCHOR.
curl --request POST \
--url https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"cert_pem": "-----BEGIN CERTIFICATE-----\nMIICQzCCAcmgAwIBAgIQ...\n-----END CERTIFICATE-----"
}
'import requests
url = "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors"
payload = { "cert_pem": "-----BEGIN CERTIFICATE-----
MIICQzCCAcmgAwIBAgIQ...
-----END CERTIFICATE-----" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
cert_pem: '-----BEGIN CERTIFICATE-----\nMIICQzCCAcmgAwIBAgIQ...\n-----END CERTIFICATE-----'
})
};
fetch('https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cert_pem' => '-----BEGIN CERTIFICATE-----
MIICQzCCAcmgAwIBAgIQ...
-----END CERTIFICATE-----'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors"
payload := strings.NewReader("{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}"
response = http.request(request)
puts response.read_body{
"id": "9c4e2f7a-8b1d-4e6c-a3f5-2d8b7c9e4f1a",
"activated_at": "2026-02-01T09:05:00Z"
}{
"code": 401,
"message": "No valid means of authentication was provided",
"classifier": "UNAUTHORIZED"
}{
"code": 403,
"message": "Not allowed to access this resource or feature",
"classifier": "FORBIDDEN"
}{
"code": 422,
"classifier": "VALIDATION_ERROR",
"message": "Validation error",
"validation_errors": [
{
"path": "json-path",
"message": "human readable error message"
}
]
}Authorizations
JWT bearer token obtained via the OAuth2 client-credentials grant from the platform Authentication API. The token's scopes gate the endpoints it may call, and its audience names the Guardian instance. This is the standard way to authenticate to Guardian.
Body
PEM-encoded X.509 certificate to install as the active Apple Root CA trust anchor.
"-----BEGIN CERTIFICATE-----\nMIICQzCCAcmgAwIBAgIQ...\n-----END CERTIFICATE-----"
curl --request POST \
--url https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"cert_pem": "-----BEGIN CERTIFICATE-----\nMIICQzCCAcmgAwIBAgIQ...\n-----END CERTIFICATE-----"
}
'import requests
url = "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors"
payload = { "cert_pem": "-----BEGIN CERTIFICATE-----
MIICQzCCAcmgAwIBAgIQ...
-----END CERTIFICATE-----" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
cert_pem: '-----BEGIN CERTIFICATE-----\nMIICQzCCAcmgAwIBAgIQ...\n-----END CERTIFICATE-----'
})
};
fetch('https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'cert_pem' => '-----BEGIN CERTIFICATE-----
MIICQzCCAcmgAwIBAgIQ...
-----END CERTIFICATE-----'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors"
payload := strings.NewReader("{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{instance}.{env}.on-hellgate.cloud/api/wallet/apple-pay/trust-anchors")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"cert_pem\": \"-----BEGIN CERTIFICATE-----\\nMIICQzCCAcmgAwIBAgIQ...\\n-----END CERTIFICATE-----\"\n}"
response = http.request(request)
puts response.read_body{
"id": "9c4e2f7a-8b1d-4e6c-a3f5-2d8b7c9e4f1a",
"activated_at": "2026-02-01T09:05:00Z"
}{
"code": 401,
"message": "No valid means of authentication was provided",
"classifier": "UNAUTHORIZED"
}{
"code": 403,
"message": "Not allowed to access this resource or feature",
"classifier": "FORBIDDEN"
}{
"code": 422,
"classifier": "VALIDATION_ERROR",
"message": "Validation error",
"validation_errors": [
{
"path": "json-path",
"message": "human readable error message"
}
]
}