Register a public key on a credential

Registering a key widens access, so it only becomes usable after an 18h grace period (activeFrom). Existing keys keep working in the meantime, so a planned rotation has no 401 window.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

tenantIdstringRequired

Tenant identifier (same value as X-Tenant-Id).

clientIdstringRequired

Credential (client_id) the subresource belongs to.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
Idempotency-KeystringOptional

Optional client-generated idempotency token (recommended for safe retries).

Request

This endpoint expects an object.
publicKeyPemstringRequired

SPKI PEM (-----BEGIN PUBLIC KEY-----) of an EC P-256 or RSA >= 2048 key. A private-key PEM is rejected explicitly.

Response

Key registered, pending the grace period.
kidstring

SHA-256 of the public key DER, truncated to 16 bytes. Derived, so you can recompute it offline and confirm you uploaded the right key.

algenum
statusenum
activeFromdatetimeOptional

When the key becomes usable (18h after registration).

createdAtdatetimeOptional
retiredAtdatetime or nullOptional

Errors

403
Forbidden Error
409
Conflict Error
422
Unprocessable Entity Error