Keys
List signing keys
GET
managementKeyheader
AuthorizationBearer <token>A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).
Nylorun-Protocol*stringThe protocol version, 8
Standby, current, previous and revoked keys
application/json- response
keys*array<>import { createAdmin } from "@nylorun/admin";const admin = createAdmin();const signingKeys = await admin.signingKeys.list();{ "keys": [ { "id": "string", "state": "standby", "alg": "ES256", "publicKey": { "kty": "EC", "crv": "P-256", "x": "string", "y": "string", "kid": "string", "alg": "ES256", "use": "sig" }, "createdAt": "string", "activatedAt": "string", "retiredAt": "string", "revokedAt": "string" } ]}Delete an application key DELETE
The key stops authenticating at once. A management key, `studio` and `bootstrap` are refused.
Rotate the signing keys POST
The standby key signs from now on; the current one still verifies tokens it signed. `force` also ends every outstanding capability link and run token.