OUTCOME · Create or advance
What changes
Creates or advances only the step-up authorization resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Developer access
/api/v2/security/step-upPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this immediately before a sensitive operation that explicitly requires a fresh purpose-bound step-up grant; the returned authorization is short-lived and cannot be reused for another purpose.
OUTCOME · Create or advance
Creates or advances only the step-up authorization resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Public service metadata, the OpenAPI document, the capability registry, guides, SDK listings, bearer credentials, step-up grants, and request-signing keys are separate artifacts. Discovery metadata grants no tenant, wallet, custody, payment, settlement, publisher, matching, or trading authority; public signing-key metadata never includes private key material.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the security:write scope.EXAMPLEBearer hc_live_…
purposebodyRequiredpurpose enumExact sensitive operation this five-minute authorization may approve, including signing-key, authenticator, password, session, federation, workload-client, platform-policy, or account lifecycle actions.
authenticator_codebodyRequired6-digit TOTPFresh second-factor code; never retained by the gateway.
REQUEST
{
"purpose": "API_SIGNING_KEY_REGISTRATION",
"authenticator_code": "123456"
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published identity-security schema.invalid_security_requestThe session, scope, public key, proof, or purpose-bound security request is invalid.invalid_credentialsThe bearer, client assertion, or proof-of-possession credential is invalid.step_up_requiredFresh purpose-bound authenticator verification or stronger authority is required.signing_key_not_foundThe requested signing-key or workload-client resource was not found.security_conflictThe requested identity-security transition conflicts with current state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"step_up_token": "hcsu_…",
"authorization_id": "9ad33a4fa6d846d88ba00c01c58ed710",
"expires_in": 300,
"expires_at": "2026-08-10T21:05:00Z"
}{
"code": "invalid_security_request",
"message": "The purpose or authenticator code is malformed."
}invalid_security_request{
"code": "invalid_credentials",
"message": "The bearer credential or authenticator code is invalid."
}invalid_credentials{
"code": "identity_security_unavailable",
"message": "Identity security is unavailable."
}identity_security_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗