Register Key
curl --request POST \
--url https://api.truthlocks.com/v1/issuers/{id}/keys \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"kid": "es256-key-1",
"algorithm": "ES256",
"public_key": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE..."
}
'import requests
url = "https://api.truthlocks.com/v1/issuers/{id}/keys"
payload = {
"kid": "es256-key-1",
"algorithm": "ES256",
"public_key": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE..."
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
kid: 'es256-key-1',
algorithm: 'ES256',
public_key: 'MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...'
})
};
fetch('https://api.truthlocks.com/v1/issuers/{id}/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/issuers/{id}/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'kid' => 'es256-key-1',
'algorithm' => 'ES256',
'public_key' => 'MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/issuers/{id}/keys"
payload := strings.NewReader("{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/issuers/{id}/keys")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/issuers/{id}/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}"
response = http.request(request)
puts response.read_body{
"kid": "<string>",
"issuer_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"algorithm": "Ed25519",
"public_key": "<string>",
"status": "ACTIVE",
"not_before": "2023-11-07T05:31:56Z",
"expires_at": "2023-11-07T05:31:56Z"
}{
"code": "VALIDATION_ERROR",
"message": "Unsupported algorithm. Must be one of: ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512, Ed25519",
"http_status": 400
}Issuers
Register Key
Registers a new cryptographic key for an issuer. Supports ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512, and Ed25519.
POST
/
v1
/
issuers
/
{id}
/
keys
Register Key
curl --request POST \
--url https://api.truthlocks.com/v1/issuers/{id}/keys \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"kid": "es256-key-1",
"algorithm": "ES256",
"public_key": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE..."
}
'import requests
url = "https://api.truthlocks.com/v1/issuers/{id}/keys"
payload = {
"kid": "es256-key-1",
"algorithm": "ES256",
"public_key": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE..."
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
kid: 'es256-key-1',
algorithm: 'ES256',
public_key: 'MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...'
})
};
fetch('https://api.truthlocks.com/v1/issuers/{id}/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/issuers/{id}/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'kid' => 'es256-key-1',
'algorithm' => 'ES256',
'public_key' => 'MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/issuers/{id}/keys"
payload := strings.NewReader("{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/issuers/{id}/keys")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/issuers/{id}/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"kid\": \"es256-key-1\",\n \"algorithm\": \"ES256\",\n \"public_key\": \"MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE...\"\n}"
response = http.request(request)
puts response.read_body{
"kid": "<string>",
"issuer_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"algorithm": "Ed25519",
"public_key": "<string>",
"status": "ACTIVE",
"not_before": "2023-11-07T05:31:56Z",
"expires_at": "2023-11-07T05:31:56Z"
}{
"code": "VALIDATION_ERROR",
"message": "Unsupported algorithm. Must be one of: ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512, Ed25519",
"http_status": 400
}Registers a new cryptographic signing key for an issuer. Keys start in ACTIVE status and can be used immediately for signing attestations.
Supported Algorithms
| Algorithm | Type | Use Case |
|---|---|---|
| Ed25519 | EdDSA | Default. Fastest signatures, smallest keys. Recommended for most use cases. |
| ES256 | ECDSA P-256 | Widely supported. Compatible with WebCrypto, mobile SDKs. |
| ES384 | ECDSA P-384 | Government/CNSA Suite. Required for some procurement contracts. |
| ES512 | ECDSA P-521 | Maximum ECDSA security. Larger signatures. |
| RS256 | RSA PKCS#1v1.5 | Legacy compatibility. Interop with older PKI systems. |
| RS384 | RSA SHA-384 | Higher security RSA with SHA-384. |
| RS512 | RSA SHA-512 | Higher security RSA with SHA-512. |
| PS256 | RSA-PSS | Modern RSA. NIST recommended replacement for PKCS#1v1.5. |
| PS384 | RSA-PSS SHA-384 | Higher security RSA-PSS. |
| PS512 | RSA-PSS SHA-512 | Maximum RSA security. |
Ed25519 is the default and recommended for new projects. Use ES384 for government/regulated industries. Use PS256 over RS256 for new RSA deployments. RS256 is available for backward compatibility only.
Parameters
string
required
The UUID of the issuer to register the key for
string
required
Unique key identifier (e.g., “ed-key-1”)
string
required
Signing algorithm. One of:
Ed25519, ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512.string
required
Base64-encoded public key
Responses
Authorizations
APIKeyBearerAuth
API key for machine-to-machine authentication
Path Parameters
Body
application/json
Response
Key registered
Key identifier
Signing algorithm for key generation
Available options:
Ed25519, ES256, ES384, ES512, RS256, RS384, RS512, PS256, PS384, PS512 Base64-encoded public key
Available options:
ACTIVE, DISABLED, EXPIRED 
