> ## Documentation Index
> Fetch the complete documentation index at: https://infisical-saif-age2-52-add-websocket-support-for-agent-proxy.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Refresh SPIFFE Trust Bundle

> Force-refresh the cached SPIFFE trust bundle for a remote-configured machine identity



## OpenAPI

````yaml POST /api/v1/auth/spiffe-auth/identities/{identityId}/refresh-bundle
openapi: 3.0.3
info:
  title: Infisical API
  description: List of all available APIs that can be consumed
  version: 0.0.1
servers:
  - url: https://us.infisical.com
    description: Production server (US)
  - url: https://eu.infisical.com
    description: Production server (EU)
  - url: http://localhost:8080
    description: Local server
security: []
paths:
  /api/v1/auth/spiffe-auth/identities/{identityId}/refresh-bundle:
    post:
      tags:
        - SPIFFE Auth
      description: >-
        Force-refresh the cached SPIFFE trust bundle for a remote-configured
        machine identity
      operationId: refreshSpiffeBundle
      parameters:
        - schema:
            type: string
          in: path
          name: identityId
          required: true
          description: >-
            The ID of the machine identity to force-refresh the cached SPIFFE
            trust bundle for.
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  identitySpiffeAuth:
                    type: object
                    properties:
                      id:
                        type: string
                        format: uuid
                      identityId:
                        type: string
                        format: uuid
                      trustDomain:
                        type: string
                      allowedSpiffeIds:
                        type: string
                      allowedAudiences:
                        type: string
                      accessTokenTTL:
                        type: number
                        default: 7200
                      accessTokenMaxTTL:
                        type: number
                        default: 7200
                      accessTokenNumUsesLimit:
                        type: number
                        default: 0
                      accessTokenTrustedIps: {}
                      createdAt:
                        type: string
                        format: date-time
                      updatedAt:
                        type: string
                        format: date-time
                      trustBundleDistribution:
                        anyOf:
                          - type: object
                            properties:
                              profile:
                                type: string
                                enum:
                                  - static
                              bundle:
                                type: string
                            required:
                              - profile
                              - bundle
                            additionalProperties: false
                          - type: object
                            properties:
                              profile:
                                type: string
                                enum:
                                  - https_web_bundle
                              endpointUrl:
                                type: string
                              caCert:
                                type: string
                              refreshHintSeconds:
                                type: number
                              cachedBundleLastRefreshedAt:
                                type: string
                                format: date-time
                                nullable: true
                            required:
                              - profile
                              - endpointUrl
                              - caCert
                              - refreshHintSeconds
                            additionalProperties: false
                    required:
                      - id
                      - identityId
                      - trustDomain
                      - allowedSpiffeIds
                      - allowedAudiences
                      - createdAt
                      - updatedAt
                      - trustBundleDistribution
                    additionalProperties: false
                required:
                  - identitySpiffeAuth
                additionalProperties: false
        '400':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 400
                  message:
                    type: string
                  error:
                    type: string
                  details: {}
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 401
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 403
                  message:
                    type: string
                  details: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 404
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
        '422':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 422
                  message: {}
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - error
                additionalProperties: false
        '500':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  reqId:
                    type: string
                  statusCode:
                    type: number
                    enum:
                      - 500
                  message:
                    type: string
                  error:
                    type: string
                required:
                  - reqId
                  - statusCode
                  - message
                  - error
                additionalProperties: false
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: An access token in Infisical

````