Keys
Revoke a signing key
POST
managementKeyheader
AuthorizationBearer <token>A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).
kid*stringNylorun-Protocol*stringThe protocol version, 8
application/json- body
requestId*stringLength
1 <= lengthThe key, revoked
application/json- response
id*stringstate*stringValue in
"standby""current""previous""revoked"alg*"ES256"Value in
"ES256"publicKey*createdAt*stringactivatedAt*string|nullretiredAt*string|nullrevokedAt*string|nullimport { createAdmin } from "@nylorun/admin";const admin = createAdmin();await admin.signingKeys.revoke("key_2026_09");{ "id": "string", "state": "standby", "alg": "ES256", "publicKey": { "kty": "EC", "crv": "P-256", "x": "string", "y": "string", "kid": "string", "alg": "ES256", "use": "sig" }, "createdAt": "string", "activatedAt": "string", "retiredAt": "string", "revokedAt": "string"}