> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a Runner pairing code

> Mints a short-lived, single-use RunnerPairing that names the active owning Principal for a person who will run a BYOC Runner on their own machine (D169). Redeeming the code mints a workspace-scoped Runner credential whose enrollment carries a server-stamped owner ceiling — the redeemer never asserts the Principal, and a supplied `runner_enrollment` must be BYOC and must not carry an owner. Returns the pairing ID plus its human-typable code exactly once, with 201; only the code digest is retained. `expires_in_seconds` accepts 120 to 600 and defaults inside that window. `Idempotency-Key` is required, and replaying the same key returns the same code.

Checkfu support posture: preview; rollout_fenced. Required evidence journey: managed-runner. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json post /v1/runner-pairings
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: sandboxProfiles
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/runner-pairings:
    post:
      tags:
        - runnerPools
      summary: Create a Runner pairing code
      description: >-
        Mints a short-lived, single-use RunnerPairing that names the active
        owning Principal for a person who will run a BYOC Runner on their own
        machine (D169). Redeeming the code mints a workspace-scoped Runner
        credential whose enrollment carries a server-stamped owner ceiling — the
        redeemer never asserts the Principal, and a supplied `runner_enrollment`
        must be BYOC and must not carry an owner. Returns the pairing ID plus
        its human-typable code exactly once, with 201; only the code digest is
        retained. `expires_in_seconds` accepts 120 to 600 and defaults inside
        that window. `Idempotency-Key` is required, and replaying the same key
        returns the same code.


        Checkfu support posture: preview; rollout_fenced. Required evidence
        journey: managed-runner. Deployment-specific readiness and the latest
        proven release are available from GET /v1/support/capabilities.
      operationId: runnerPools.createRunnerPairing
      parameters:
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
        - name: idempotency-key
          in: header
          schema:
            type: string
            allOf:
              - maxLength: 255
              - minLength: 1
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                principal_id:
                  $ref: '#/components/schemas/PrincipalId'
                machine_label:
                  type: string
                  allOf:
                    - minLength: 1
                    - maxLength: 120
                expires_in_seconds:
                  type: integer
                  allOf:
                    - minimum: 120
                    - maximum: 600
                runner_enrollment:
                  $ref: '#/components/schemas/Objects_6'
              required:
                - principal_id
              additionalProperties: false
        required: true
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    $ref: '#/components/schemas/RunnerPairingId'
                  code:
                    type: string
                    allOf:
                      - pattern: >-
                          ^CFU-[ABCDEFGHJKLMNPQRSTUVWXYZ23456789]{5}(?:-[ABCDEFGHJKLMNPQRSTUVWXYZ23456789]{5}){3}$
                  expires_at:
                    type: string
                required:
                  - id
                  - code
                  - expires_at
                additionalProperties: false
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    properties:
                      type:
                        type: string
                        enum:
                          - validation.malformed
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#validation-malformed
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    required:
                      - type
                      - message
                      - more
                    additionalProperties: false
                additionalProperties: false
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '404':
          description: >-
            The requested resource does not exist in the resolved deployment
            boundary.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationNotFoundError'
        '409':
          description: >-
            The request conflicts with the resource's current state. | An
            idempotent mutation conflicts with a completed or in-progress
            request for the same key.
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: '#/components/schemas/ValidationConflictError'
                  - $ref: '#/components/schemas/IdempotencyConflictError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    PrincipalId:
      type: string
      allOf:
        - pattern: ^prin_[0-9a-f]{32}$
    Objects_6:
      type: object
      properties:
        placement:
          $ref: '#/components/schemas/Union_18'
        providers:
          type: array
          items:
            $ref: '#/components/schemas/Objects_7'
          allOf:
            - minItems: 1
            - maxItems: 64
        plane_protocols:
          type: array
          items:
            $ref: '#/components/schemas/Union_22'
          allOf:
            - maxItems: 16
        runner_pool:
          $ref: '#/components/schemas/RunnerPoolId'
        owner:
          type: object
          properties:
            principal:
              $ref: '#/components/schemas/PrincipalId'
            machine_label:
              type: string
              allOf:
                - minLength: 1
                - maxLength: 120
          required:
            - principal
          additionalProperties: false
        placement_conformance_digests:
          $ref: '#/components/schemas/Arrays_1'
      required:
        - placement
        - providers
        - plane_protocols
      additionalProperties: false
    RunnerPairingId:
      type: string
      allOf:
        - pattern: ^rnp_[0-9a-f]{32}$
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    ValidationNotFoundError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.not_found
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-not-found
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The requested resource does not exist in the resolved deployment
        boundary.
    ValidationConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.conflict
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The request conflicts with the resource's current state.
    IdempotencyConflictError:
      anyOf:
        - $ref: '#/components/schemas/ValidationIdempotencyConflictError'
        - $ref: '#/components/schemas/ValidationIdempotencyInProgressError'
      description: >-
        An idempotent mutation conflicts with a completed or in-progress request
        for the same key.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    Union_18:
      type: string
      enum:
        - local
        - hosted
        - byoc
    Objects_7:
      type: object
      properties:
        id:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 255
        provider_revision:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 255
        materialization_revision:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 255
        browser_observation:
          $ref: '#/components/schemas/BrowserProviderObservationCapabilities'
        desktop_observation:
          $ref: '#/components/schemas/DesktopProviderObservationCapabilities'
        drivers:
          type: array
          items:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 255
          allOf:
            - minItems: 1
            - maxItems: 256
        harness_owned_models:
          type: array
          items:
            type: object
            properties:
              kind:
                type: string
                enum:
                  - cursor_api_key
              harness_profile_id:
                $ref: '#/components/schemas/HarnessProfileId'
              harness_profile_revision_number:
                type: integer
                allOf:
                  - exclusiveMinimum: 0
              harness_release_digest:
                type: string
                allOf:
                  - pattern: ^sha256:[0-9a-f]{64}$
              provider:
                type: string
                enum:
                  - cursor
              model:
                type: string
                allOf:
                  - minLength: 1
                  - maxLength: 255
            required:
              - kind
              - harness_profile_id
              - harness_profile_revision_number
              - harness_release_digest
              - provider
              - model
            additionalProperties: false
          allOf:
            - maxItems: 64
        launch_kinds:
          type: array
          items:
            type: string
            enum:
              - trusted
              - oci
          allOf:
            - minItems: 1
        tiers:
          type: array
          items:
            $ref: '#/components/schemas/Union_19'
          allOf:
            - minItems: 1
        platforms:
          type: array
          items:
            $ref: '#/components/schemas/Objects_8'
          allOf:
            - minItems: 1
        network_modes:
          type: array
          items:
            $ref: '#/components/schemas/Union_20'
          allOf:
            - minItems: 1
        retention_modes:
          type: array
          items:
            $ref: '#/components/schemas/Union_21'
          allOf:
            - minItems: 1
        session_sandbox:
          type: boolean
        runtime_assurances:
          $ref: '#/components/schemas/Objects_9'
        acp_transport:
          type: string
          enum:
            - stdio
            - stdio-tunnel
            - network
        snapshot_clone:
          type: boolean
        snapshot_custody:
          type: string
          enum:
            - runner
            - provider
        package_materialization:
          type: boolean
        max_mounts:
          type: integer
          allOf:
            - minimum: 0
        mount_kinds:
          type: array
          items:
            type: string
            enum:
              - uploaded_project
              - git
              - memory
              - skills
              - file
          allOf:
            - maxItems: 5
        minimum_resources:
          $ref: '#/components/schemas/Objects_10'
        maximum_resources:
          $ref: '#/components/schemas/Objects_10'
      required:
        - id
        - provider_revision
        - materialization_revision
        - drivers
        - launch_kinds
        - tiers
        - platforms
        - network_modes
        - retention_modes
        - package_materialization
        - max_mounts
        - minimum_resources
        - maximum_resources
      additionalProperties: false
    Union_22:
      type: string
      enum:
        - model-gateway-v1
        - platform-mcp-v1
        - platform-control-mcp-v2
    RunnerPoolId:
      type: string
      allOf:
        - pattern: ^rpool_[0-9a-f]{32}$
    Arrays_1:
      type: array
      items:
        type: string
        allOf:
          - pattern: ^sha256:[0-9a-f]{64}$
      allOf:
        - maxItems: 256
    ValidationIdempotencyConflictError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_conflict
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-conflict
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: The Idempotency-Key is already bound to a different request.
    ValidationIdempotencyInProgressError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.idempotency_in_progress
            message:
              type: string
            more:
              type: string
              enum:
                - >-
                  https://docs.checkfu.com/reference/errors#validation-idempotency-in-progress
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An identical idempotent request is still in progress and may be retried
        later.
    BrowserProviderObservationCapabilities:
      type: object
      properties:
        accessibility_tree:
          type: boolean
        screenshot:
          type: boolean
      required:
        - accessibility_tree
        - screenshot
      additionalProperties: false
    DesktopProviderObservationCapabilities:
      type: object
      properties:
        accessibility_tree:
          type: boolean
        screenshot:
          type: boolean
        window_inventory:
          type: boolean
      required:
        - accessibility_tree
        - screenshot
        - window_inventory
      additionalProperties: false
    HarnessProfileId:
      type: string
      allOf:
        - pattern: ^hprof_[0-9a-f]{32}$
    Union_19:
      type: string
      enum:
        - container
        - microvm
    Objects_8:
      type: object
      properties:
        os:
          type: string
          enum:
            - linux
        architecture:
          type: string
          enum:
            - amd64
            - arm64
      required:
        - os
        - architecture
      additionalProperties: false
    Union_20:
      type: string
      enum:
        - none
        - allowlist
        - unrestricted
    Union_21:
      type: string
      enum:
        - durable
        - ephemeral_zdr
    Objects_9:
      type: object
      properties:
        compute_accounting:
          type: boolean
        network_isolation:
          type: boolean
        bounded_start:
          type: boolean
        bounded_cancel:
          type: boolean
        teardown:
          type: boolean
      required:
        - compute_accounting
        - network_isolation
        - bounded_start
        - bounded_cancel
        - teardown
      additionalProperties: false
    Objects_10:
      type: object
      properties:
        cpu_millis:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        memory_mib:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        disk_mib:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        max_duration_seconds:
          type: integer
          allOf:
            - exclusiveMinimum: 0
      required:
        - cpu_millis
        - memory_mib
        - disk_mib
        - max_duration_seconds
      additionalProperties: false
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````