OUTCOME · Create or advance
What changes
Creates or advances only the request-signing key resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Developer access
/api/v2/security/signing-keys/{key_id}/revocationsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this with a fresh purpose-bound step-up grant when a request-signing key is compromised, retired, superseded, or no longer permitted to authorize signed requests.
OUTCOME · Create or advance
Creates or advances only the request-signing key resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Public service metadata, the OpenAPI document, the capability registry, guides, SDK listings, bearer credentials, step-up grants, and request-signing keys are separate artifacts. Discovery metadata grants no tenant, wallet, custody, payment, settlement, publisher, matching, or trading authority; public signing-key metadata never includes private key material.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the security:write scope.EXAMPLEBearer hc_live_…
key_idpathRequiredhck_ identifierActive signing key to revoke.
step_up_tokenbodyRequiredhcsu_ purpose-bound tokenFresh API_SIGNING_KEY_REVOCATION authorization.
REQUEST
{
"step_up_token": "hcsu_…"
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published identity-security schema.invalid_security_requestThe session, scope, public key, proof, or purpose-bound security request is invalid.invalid_credentialsThe bearer, client assertion, or proof-of-possession credential is invalid.step_up_requiredFresh purpose-bound authenticator verification or stronger authority is required.signing_key_not_foundThe requested signing-key or workload-client resource was not found.security_conflictThe requested identity-security transition conflicts with current state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"key_id": "hck_…",
"status": "REVOKED"
}{
"code": "invalid_security_request",
"message": "The request shape is invalid."
}invalid_security_request{
"code": "invalid_credentials",
"message": "The bearer credential is invalid."
}invalid_credentials{
"code": "step_up_required",
"message": "A matching fresh step-up authorization is required."
}step_up_required{
"code": "signing_key_not_found",
"message": "The active key does not exist for this identity and client."
}signing_key_not_found{
"code": "identity_security_unavailable",
"message": "Identity security is unavailable."
}identity_security_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗