Register a Server Signing Key for a server identity
Registers a P-256 public key for the named server identity (serverId). Dashboard admin JWT only; API tokens are rejected. The server fetches its own assertion on first use. Revoked keys cannot be re-registered.
POST
Register a Server Signing Key for a server identity
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
ID of the environment
Required string length:
36Pattern:
^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$Example:
"95b11417-f18f-457f-8804-68e361f9164f"
Body
application/json
Required string length:
36Pattern:
^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$Example:
"95b11417-f18f-457f-8804-68e361f9164f"
P-256 public key as SEC1 hex, compressed (33 bytes) or uncompressed (65 bytes)
Pattern:
^(0[23][0-9a-fA-F]{64}|04[0-9a-fA-F]{128})$Maximum string length:
255Response
The registered key
Required string length:
36Pattern:
^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$Example:
"95b11417-f18f-457f-8804-68e361f9164f"
RFC 7638 thumbprint of the public key; the JWS kid of operation proofs
Available options:
active, expired, revoked Last modified on October 8, 2026