# Claim WireGuard Configuration After Payment Settlement

## OpenAPI Specification

```yaml
openapi: 3.0.1
info:
  title: ''
  description: ''
  version: 1.0.0
paths:
  /api/public/v1/subscription/claim:
    post:
      summary: Claim WireGuard Configuration After Payment Settlement
      deprecated: false
      description: >-
        Provisions or retrieves the WireGuard configuration once the Lightning
        invoice payment has settled. For orders created with a wgPublicKey, send
        the same wgPublicKey here; the response then contains only the tunnel
        parameters (server, peer, vpnPort) and never a config or private key.
        Rate limit: 10 requests/min per IP.
      tags:
        - ⚡ Purchase
        - ⚡ Purchase
      parameters:
        - name: Content-Type
          in: header
          description: Media type of the request payload. Must be application/json.
          required: true
          example: ''
          schema:
            type: string
            default: application/json
            examples:
              - application/json
        - name: Accept
          in: header
          description: Expected response media type.
          required: false
          example: ''
          schema:
            type: string
            default: application/json
            examples:
              - application/json
        - name: Authorization
          in: header
          description: >-
            Optional. Links this subscription to your account. Bearer
            sk_live_... or Nostr <base64-event>.
          required: false
          example: ''
          schema:
            type: string
            examples:
              - Bearer sk_live_a1b2c3d4e5f6g7h8i9j0
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - paymentHash
              properties:
                paymentHash:
                  type: string
                  description: Payment hash from the /create response.
                  examples:
                    - >-
                      0b9af6ab9d3c7d6146e3f28ca11bf4b830f4cab95330c5a5c9b25b7827afc44c
                wgPublicKey:
                  type: string
                  description: >-
                    Your WireGuard public key (44-char Base64). Required, and
                    must match, if the order was created with a wgPublicKey.
                    Otherwise optional; if omitted, keys are generated
                    server-side. Omit the field rather than sending null.
                  examples:
                    - hnG/fWsNx7DiVbGUj3B/i0EtXvpIZdO5cuoQJCTWhRU=
              x-apidog-orders:
                - paymentHash
                - wgPublicKey
              x-apidog-ignore-properties: []
      responses:
        '200':
          description: WireGuard configuration provisioned
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClaimResult'
          headers: {}
          x-apidog-name: OK
        '202':
          description: >-
            Payment confirmed, provisioning in progress (client-held key
            orders). Retry the claim.
          content:
            application/json:
              schema:
                type: object
                properties:
                  paymentHash:
                    type: string
                  status:
                    type: string
                    examples:
                      - processing
                  message:
                    type: string
                x-apidog-orders:
                  - paymentHash
                  - status
                  - message
                x-apidog-ignore-properties: []
          headers: {}
          x-apidog-name: ''
        '402':
          description: Invoice not yet paid
          content:
            application/json:
              schema: &ref_0
                $ref: '#/components/schemas/ApiError'
          headers: {}
          x-apidog-name: Record Not Found
        '404':
          description: Subscription not found
          content:
            application/json:
              schema: *ref_0
          headers: {}
          x-apidog-name: ''
        '409':
          description: wgPublicKey missing or different from the key registered at /create
          content:
            application/json:
              schema: *ref_0
          headers: {}
          x-apidog-name: ''
      security: []
      x-apidog-folder: ⚡ Purchase
      x-apidog-status: released
      x-run-in-apidog: https://app.eu.apidog.com/web/project/361232/apis/api-4483133-run
components:
  schemas:
    ClaimResult:
      type: object
      required:
        - status
      properties:
        config:
          type: string
          description: >-
            WireGuard configuration file contents (legacy orders on
            already_processed only).
          examples:
            - |-
              [Interface]
              PrivateKey = ...
              Address = 10.9.0.2/32
              DNS = 1.1.1.1

              [Peer]
              PublicKey = ...
              Endpoint = de2.tunnelsats.com:51820
              AllowedIPs = 0.0.0.0/0
        fullConfig:
          type: string
          description: Full dual-key WireGuard config (if applicable).
          nullable: true
        status:
          type: string
          enum:
            - success
            - already_processed
          examples:
            - success
        subscriptionEnd:
          type: string
          format: date-time
          examples:
            - '2027-01-01T00:00:00.000Z'
        server:
          type: object
          properties:
            endpoint:
              type: string
              examples:
                - de2.tunnelsats.com:51820
            publicKey:
              type: string
              description: Server WireGuard public key.
            allowedIPs:
              type: string
              examples:
                - 0.0.0.0/0, ::/0
          x-apidog-orders:
            - endpoint
            - publicKey
            - allowedIPs
          x-apidog-ignore-properties: []
        peer:
          type: object
          properties:
            address:
              type: string
              description: Tunnel IP of your interface.
              examples:
                - 10.9.0.7
            publicKey:
              type: string
              description: Echo of your registered public key (client-held key orders).
            presharedKey:
              type: string
              description: Server-generated preshared key.
          x-apidog-orders:
            - address
            - publicKey
            - presharedKey
          x-apidog-ignore-properties: []
        vpnPort:
          type: integer
          description: Public port forwarded to your node through the tunnel.
          examples:
            - 24556
      description: >-
        Legacy orders return `config`/`fullConfig`. Orders created with a
        wgPublicKey return only `server`, `peer` and `vpnPort`; `config` is
        absent and `fullConfig` is null.
      x-apidog-orders:
        - config
        - fullConfig
        - status
        - subscriptionEnd
        - server
        - peer
        - vpnPort
      x-apidog-ignore-properties: []
      x-apidog-folder: ''
    ApiError:
      type: object
      required:
        - error
        - message
      properties:
        error:
          type: string
          description: Standard machine-readable error code.
          examples:
            - ERR_RATE_LIMIT_EXCEEDED
        message:
          type: string
          description: Human-readable error explanation.
          examples:
            - Rate limit exceeded. Please wait before retrying.
        details:
          type: object
          description: Optional validation error details or parameters.
          x-apidog-orders: []
          properties: {}
          x-apidog-ignore-properties: []
          nullable: true
      x-apidog-orders:
        - error
        - message
        - details
      x-apidog-ignore-properties: []
      x-apidog-folder: ''
  securitySchemes:
    ApiKeyAuth:
      type: bearer
      scheme: bearer
      description: Authenticate using your TunnelSats API Key (sk_live_...).
    NostrAuth:
      type: bearer
      scheme: bearer
      description: >-
        NIP-98 Nostr Authentication. The token is the base64-encoded NIP-98
        event JSON.
servers:
  - url: https://tunnelsats.com
    description: Prod Env
security: []

```