Skip to main content
GET
Get one of the environment's Server Signing Keys

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

keyId
string
required

Registry id of the key (not its kid)

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Response

The key

id
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

kid
string
required

RFC 7638 thumbprint of the public key; the JWS kid of operation proofs

label
string | null
required
publicSigningKey
string
required
status
enum<string>
required
Available options:
active,
expired,
revoked
createdAt
string<date-time>
required
revokedAt
string<date-time> | null
required
Last modified on October 8, 2026