Register a public key on a credential
Registering a key widens access, so it only becomes usable after an
18h grace period (activeFrom). Existing keys keep working in the
meantime, so a planned rotation has no 401 window.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
Tenant identifier (same value as X-Tenant-Id).
Credential (client_id) the subresource belongs to.
Headers
Optional client-generated idempotency token (recommended for safe retries).
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Request
SPKI PEM (-----BEGIN PUBLIC KEY-----) of an EC P-256 or RSA >= 2048 key. A private-key PEM is rejected explicitly.
Response
SHA-256 of the public key DER, truncated to 16 bytes. Derived, so you can recompute it offline and confirm you uploaded the right key.
When the key becomes usable (18h after registration).