Skip to main content
POST
Register a Server Signing Key for a server identity

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Body

application/json
serverId
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

publicSigningKey
string
required

P-256 public key as SEC1 hex, compressed (33 bytes) or uncompressed (65 bytes)

Pattern: ^(0[23][0-9a-fA-F]{64}|04[0-9a-fA-F]{128})$
label
string | null
Maximum string length: 255

Response

The registered key

id
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

kid
string
required

RFC 7638 thumbprint of the public key; the JWS kid of operation proofs

label
string | null
required
publicSigningKey
string
required
status
enum<string>
required
Available options:
active,
expired,
revoked
createdAt
string<date-time>
required
revokedAt
string<date-time> | null
required
Last modified on October 8, 2026