NylorunDocsBeta
Management APIKeys

Revoke a signing key

POST
/v1/tenant/signing-keys/{kid}/revoke

Authorization

managementKey
headerAuthorizationBearer <token>

A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).

Path Parameters

kid*string

Header Parameters

Nylorun-Protocol*string

The protocol version, 8

Request Body

application/json
  1. body
requestId*string
Length1 <= length

Response Body

The key, revoked

application/json
  1. response
id*string
state*string
Value in"standby""current""previous""revoked"
alg*"ES256"
Value in"ES256"
publicKey*
createdAt*string
activatedAt*string|null
retiredAt*string|null
revokedAt*string|null
import { createAdmin } from "@nylorun/admin";const admin = createAdmin();await admin.signingKeys.revoke("key_2026_09");
{  "id": "string",  "state": "standby",  "alg": "ES256",  "publicKey": {    "kty": "EC",    "crv": "P-256",    "x": "string",    "y": "string",    "kid": "string",    "alg": "ES256",    "use": "sig"  },  "createdAt": "string",  "activatedAt": "string",  "retiredAt": "string",  "revokedAt": "string"}