> ## Documentation Index
> Fetch the complete documentation index at: https://developer.hellgate.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Replace trust anchor

> Replace the active Apple Root CA trust anchor Guardian verifies payment payloads against. The instance ships with Apple's current root CA seeded, so you only need this if Apple rotates its root certificate. The previous anchor is superseded atomically.

A PEM that cannot be decoded as a valid X.509 certificate returns `422` with the classifier `APPLE_PAY_INVALID_TRUST_ANCHOR`.




## OpenAPI

````yaml /products/guardian/openapi.yaml post /api/wallet/apple-pay/trust-anchors
openapi: 3.1.0
info:
  title: Guardian API
  version: '1.0'
  contact:
    name: Starfish GmbH & Co. KG
    email: hello@starfish.team
    url: https://hellgate.io/cpa/guardian
  license:
    name: Hellgate API Terms
    url: https://hellgate.io/terms-and-conditions
servers:
  - url: https://{cluster_id}.on-hellgate.cloud
    description: Guardian service instance
    variables:
      cluster_id:
        default: my-cluster-id
        description: |
          Guardian is a service of the Hellgate Cloud Platform.
          The unique cluster-id is used to connect to your instance.
security: []
tags:
  - name: pci
    description: Management of card payment credentials under the ruling of PCI DSS.
  - name: network
    description: Management of network tokens and cryptograms for secure transactions.
  - name: generic
    description: Management of generic tokens and their schemas for various use cases.
  - name: metadata
    description: Inquiries for card metadata based on PAN, PCI tokens, or network tokens.
  - name: wallet
    description: >-
      Management of wallet tokens ingested from device wallets such as Google
      Pay.
  - name: apikey
    description: Management of API keys for service access.
  - name: webhook
    description: Management of webhooks for event notifications.
  - name: types
    description: Management of types for generic token schemas.
paths:
  /api/wallet/apple-pay/trust-anchors:
    post:
      tags:
        - wallet
      summary: Replace trust anchor
      description: >
        Replace the active Apple Root CA trust anchor Guardian verifies payment
        payloads against. The instance ships with Apple's current root CA
        seeded, so you only need this if Apple rotates its root certificate. The
        previous anchor is superseded atomically.


        A PEM that cannot be decoded as a valid X.509 certificate returns `422`
        with the classifier `APPLE_PAY_INVALID_TRUST_ANCHOR`.
      operationId: wallet_apple_pay_trust_anchor_replace
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/apple_pay_trust_anchor_request'
      responses:
        '200':
          description: Success response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/apple_pay_trust_anchor'
        '401':
          $ref: '#/components/responses/401_UnauthorizedError'
        '403':
          $ref: '#/components/responses/403_ForbiddenError'
        '422':
          $ref: '#/components/responses/422_ValidationError'
      security:
        - APIKey: []
        - AdminToken: []
components:
  schemas:
    apple_pay_trust_anchor_request:
      type: object
      properties:
        cert_pem:
          type: string
          description: >-
            PEM-encoded X.509 certificate to install as the active Apple Root CA
            trust anchor.
      required:
        - cert_pem
    apple_pay_trust_anchor:
      title: Apple Pay Trust Anchor
      type: object
      properties:
        id:
          type: string
          format: uuid
        activated_at:
          type: string
          format: date-time
      required:
        - id
        - activated_at
    ErrorGeneric:
      type: object
      properties:
        code:
          $ref: '#/components/schemas/ErrorStatusCode'
        classifier:
          $ref: '#/components/schemas/ErrorClassifier'
        message:
          $ref: '#/components/schemas/ErrorMessage'
    ErrorValidation:
      type: object
      properties:
        code:
          $ref: '#/components/schemas/ErrorStatusCode'
        classifier:
          $ref: '#/components/schemas/ErrorClassifier'
        message:
          $ref: '#/components/schemas/ErrorMessage'
        validation_errors:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
                description: Json-path in the request which points to the validation error
              message:
                type: string
                description: Human readable validation message
    ErrorStatusCode:
      type: integer
      description: The corresponding HTTP status code for the error
    ErrorClassifier:
      type: string
      description: Technical code that helps to identify the error
    ErrorMessage:
      type: string
      description: Human readable representation of the error
  responses:
    401_UnauthorizedError:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorGeneric'
          example:
            code: 401
            message: No valid means of authentication was provided
            classifier: UNAUTHORIZED
    403_ForbiddenError:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorGeneric'
          example:
            code: 403
            message: Not allowed to access this resource or feature
            classifier: FORBIDDEN
    422_ValidationError:
      description: Validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorValidation'
          example:
            code: 422
            classifier: VALIDATION_ERROR
            message: Validation error
            validation_errors:
              - path: json-path
                message: human readable error message
  securitySchemes:
    APIKey:
      type: apiKey
      name: x-api-key
      in: header
    AdminToken:
      type: apiKey
      name: x-admin-token
      in: header

````