Skip to content

client.signing_keys

client.signing_keys — the signingKeys operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
include_revoked: Literal['true', 'false'] | None = None,
label: str | None = None,
timeout: float | None = None,
) -> TrustedSigningKeyPage

List trusted signing keys. GET /v1/signing-keys

Cursor-paginated. Active keys only unless ?includeRevoked=true; ?label= is a prefix match on the label.

trust(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> TrustedSigningKey

Trust a signing key. POST /v1/signing-keys

Adds a public key to the tenant's trust list: deployments it signs verify. Needs the signing-keys:write capability. Trusting the same key again answers 200; a known keyId with a different public key is 409 signing-key-conflict (rotate under a new id). Mounted when the deployment supplies a signing-key registry.

get(*, timeout: float | None = None) -> TrustedSigningKey

Get a signing key. GET /v1/signing-keys/{keyId}

Revoked keys too (with revokedAt), for audit.

revoke(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> RevokeSigningKeyResult

Revoke a signing key. POST /v1/signing-keys/{keyId}/revoke

Deployments it signed stay on record; it verifies no new ones. Needs the signing-keys:write capability. Idempotent: revoked is false when the key was unknown or already revoked.