NylorunDocsBeta
Management APIKeys

Rotate the signing keys

POST
/v1/tenant/signing-keys/rotate

The standby key signs from now on; the current one still verifies tokens it signed. force also ends every outstanding capability link and run token.

Authorization

managementKey
headerAuthorizationBearer <token>

A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).

Header Parameters

Nylorun-Protocol*string

The protocol version, 8

Request Body

application/json
  1. body
requestId*string
Length1 <= length
force?boolean

Response Body

The keys after rotation

application/json
  1. response
keys*array<>
import { createAdmin } from "@nylorun/admin";const admin = createAdmin();await admin.signingKeys.rotate();
{  "keys": [    {      "id": "string",      "state": "standby",      "alg": "ES256",      "publicKey": {        "kty": "EC",        "crv": "P-256",        "x": "string",        "y": "string",        "kid": "string",        "alg": "ES256",        "use": "sig"      },      "createdAt": "string",      "activatedAt": "string",      "retiredAt": "string",      "revokedAt": "string"    }  ]}