Register a public key on a credential
Registering a key widens access, so it only becomes usable after an
18h grace period (activeFrom). Existing keys keep working in the
meantime, so a planned rotation has no 401 window.
Authentication
AuthorizationBearer
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
tenantId
Tenant identifier (same value as X-Tenant-Id).
clientId
Credential (client_id) the subresource belongs to.
Headers
X-Tenant-Id
Tenant context used for authorization and routing.
Idempotency-Key
Optional client-generated idempotency token (recommended for safe retries).
Request
This endpoint expects an object.
publicKeyPem
SPKI PEM (-----BEGIN PUBLIC KEY-----) of an EC P-256 or RSA >= 2048 key. A private-key PEM is rejected explicitly.
Response
Key registered, pending the grace period.
kid
SHA-256 of the public key DER, truncated to 16 bytes. Derived, so you can recompute it offline and confirm you uploaded the right key.
alg
status
activeFrom
When the key becomes usable (18h after registration).
createdAt
retiredAt
Errors
403
Forbidden Error
409
Conflict Error
422
Unprocessable Entity Error