OUTCOME · Create or advance
What changes
Creates or advances only the request-signing key resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Session Management
/api/v2/security/signing-keysPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this after generating an Ed25519 key pair, retaining the private key outside Hybrid-Chain, proving possession of the public JWK, and obtaining a fresh step-up grant for key registration.
OUTCOME · Create or advance
Creates or advances only the request-signing key resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Public service metadata, the OpenAPI document, the capability registry, guides, SDK listings, bearer credentials, step-up grants, and request-signing keys are separate artifacts. Discovery metadata grants no tenant, wallet, custody, payment, settlement, publisher, matching, or trading authority; public signing-key metadata never includes private key material.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the security:write scope.EXAMPLEBearer hc_live_…
public_key_jwkbodyRequiredOKP Ed25519 public JWKPublic key with kty=OKP, crv=Ed25519, and a 32-byte unpadded base64url x value.
proofbodyRequiredunpadded base64url Ed25519 signatureProof over the domain-separated canonical registration statement.
step_up_tokenbodyRequiredhcsu_ purpose-bound tokenFresh API_SIGNING_KEY_REGISTRATION authorization.
labelbodyOptionalstring · max 160Human-readable device or machine label; defaults to API signing key.
rotated_from_key_idbodyOptionalhck_ identifierExisting key being replaced; it must belong to this identity and client.
REQUEST
{
"public_key_jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "…"
},
"proof": "…",
"step_up_token": "hcsu_…",
"label": "Production settlement worker",
"rotated_from_key_id": null
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published identity-security schema.invalid_security_requestThe session, scope, public key, proof, or purpose-bound security request is invalid.invalid_credentialsThe bearer, client assertion, or proof-of-possession credential is invalid.step_up_requiredFresh purpose-bound authenticator verification or stronger authority is required.signing_key_not_foundThe requested signing-key or workload-client resource was not found.security_conflictThe requested identity-security transition conflicts with current state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"key_id": "hck_…",
"algorithm": "ed25519",
"thumbprint": "f4a5…",
"label": "Production settlement worker",
"status": "ACTIVE",
"rotated_from_key_id": null,
"created_at": null,
"expires_at": null,
"revoked_at": null
}{
"code": "invalid_request",
"message": "The JWK or proof of possession is invalid."
}invalid_request{
"code": "invalid_credentials",
"message": "The bearer credential is invalid."
}invalid_credentials{
"code": "step_up_required",
"message": "A matching fresh step-up authorization is required."
}step_up_required{
"code": "signing_key_conflict",
"message": "The public key is already registered or the selected predecessor is invalid."
}signing_key_conflict{
"code": "identity_security_unavailable",
"message": "Identity security is unavailable."
}identity_security_unavailableOPERATIONAL NOTES
UPGRADING FROM V1
If you maintain an older integration, use this map to find the V2 replacement. Do not translate the old request field-for-field: rebuild it from the V2 parameters and schemas above because identity, authorization, replay protection, and response semantics may have changed.
/api/v1/sessions/newSESSION: Create new API KeyThis route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗