curl https://production.methodfi.com/teams/mle/public_keys \
-X POST \
-H "Method-Version: 2026-03-30" \
-H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
-H "Content-Type: application/json" \
-d '{
"type": "direct",
"contact": "security@yourcompany.com",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null
}'
const key = await method.teams.mle.publicKeys.create({
type: 'direct',
contact: 'security@yourcompany.com',
jwk: {
kid: 'your-unique-key-id',
kty: 'RSA',
alg: 'RSA-OAEP-256',
use: 'enc',
n: 's3C9N7Vz...J7c',
e: 'AQAB',
iat: 1780309800,
nbf: 1780309800,
exp: 1811845800
},
well_known_endpoint: null
});
key = method.teams.mle.public_keys.create({
'type': 'direct',
'contact': 'security@yourcompany.com',
'jwk': {
'kid': 'your-unique-key-id',
'kty': 'RSA',
'alg': 'RSA-OAEP-256',
'use': 'enc',
'n': 's3C9N7Vz...J7c',
'e': 'AQAB',
'iat': 1780309800,
'nbf': 1780309800,
'exp': 1811845800
},
'well_known_endpoint': None
})
{
"success": true,
"data": {
"id": "team_jwk_12345",
"type": "direct",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null,
"status": "active",
"contact": "security@yourcompany.com",
"created_at": "2026-06-01T10:30:00Z",
"updated_at": "2026-06-01T10:30:00Z"
},
"message": null
}
Team JWKS
Create MLE Public Key
POST
/
teams
/
mle
/
public_keys
curl https://production.methodfi.com/teams/mle/public_keys \
-X POST \
-H "Method-Version: 2026-03-30" \
-H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
-H "Content-Type: application/json" \
-d '{
"type": "direct",
"contact": "security@yourcompany.com",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null
}'
const key = await method.teams.mle.publicKeys.create({
type: 'direct',
contact: 'security@yourcompany.com',
jwk: {
kid: 'your-unique-key-id',
kty: 'RSA',
alg: 'RSA-OAEP-256',
use: 'enc',
n: 's3C9N7Vz...J7c',
e: 'AQAB',
iat: 1780309800,
nbf: 1780309800,
exp: 1811845800
},
well_known_endpoint: null
});
key = method.teams.mle.public_keys.create({
'type': 'direct',
'contact': 'security@yourcompany.com',
'jwk': {
'kid': 'your-unique-key-id',
'kty': 'RSA',
'alg': 'RSA-OAEP-256',
'use': 'enc',
'n': 's3C9N7Vz...J7c',
'e': 'AQAB',
'iat': 1780309800,
'nbf': 1780309800,
'exp': 1811845800
},
'well_known_endpoint': None
})
{
"success": true,
"data": {
"id": "team_jwk_12345",
"type": "direct",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null,
"status": "active",
"contact": "security@yourcompany.com",
"created_at": "2026-06-01T10:30:00Z",
"updated_at": "2026-06-01T10:30:00Z"
},
"message": null
}
Creates a new public key registration for Message Level Encryption. You can register your key using either direct registration (providing the JWK directly) or well-known endpoint registration (providing a URL where Method can fetch your JWKS).
Both encryption keys (
use: "enc") and signing keys (use: "sig") may be registered. Encryption keys are used to encrypt responses to you. Signing keys are used to verify the signature on your requests on the signed MLE path.
Each key ID (
kid) can only be registered once. Choose either direct or well-known registration for each unique key.Body
Well-Known Endpoint Requirements
If usingtype: "well_known", your endpoint must return a JWKS that meets these requirements:
- The document must have a top-level field named
keysthat has a list as its value. - Each JWK (an item in the list of
keys) must be an object with a field namedktyequal toRSA, a fieldnthat is a valid stringnfor a JWK in accordance with the RFC, and a fieldethat is a valid stringefor a JWK in accordance with the RFC. - Each JWK must have a field
kidand it must be a string. Keys without akidare dropped. On the standard MLE path, this value is what you pass ascidwhen making requests to Method. useis optional and defaults toenc. Bothencandsigare accepted.algis optional. If present, it must match theuse:RSA-OAEP-256forenc, andRS256forsig. A key whosealgdoes not match itsuseis dropped.iat,nbf, andexpare optional numeric claims. Method preserves them and uses them for key selection and validity checks.
kid is registered through only one of the two mechanisms, as described in the note above.
Registering a Signing Key
The signed MLE path requires a signing key in addition to an encryption key. Register it withuse: "sig" and alg: "RS256":
curl https://production.methodfi.com/teams/mle/public_keys \
-X POST \
-H "Method-Version: 2026-03-30" \
-H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
-H "Content-Type: application/json" \
-d '{
"type": "direct",
"contact": "security@yourcompany.com",
"jwk": {
"kid": "my-sig-key-2026",
"kty": "RSA",
"alg": "RS256",
"use": "sig",
"n": "p7K4R2Xb...M4a",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null
}'
const key = await method.teams.mle.publicKeys.create({
type: 'direct',
contact: 'security@yourcompany.com',
jwk: {
kid: 'my-sig-key-2026',
kty: 'RSA',
alg: 'RS256',
use: 'sig',
n: 'p7K4R2Xb...M4a',
e: 'AQAB',
iat: 1780309800,
nbf: 1780309800,
exp: 1811845800
},
well_known_endpoint: null
});
key = method.teams.mle.public_keys.create({
'type': 'direct',
'contact': 'security@yourcompany.com',
'jwk': {
'kid': 'my-sig-key-2026',
'kty': 'RSA',
'alg': 'RS256',
'use': 'sig',
'n': 'p7K4R2Xb...M4a',
'e': 'AQAB',
'iat': 1780309800,
'nbf': 1780309800,
'exp': 1811845800
},
'well_known_endpoint': None
})
Register an
iat on every encryption key if more than one will ever be active at a time: on the signed MLE path Method selects the response encryption key by the highest iat among in-window keys, and a tie with no iat fails with MLE_ENCRYPTION_KEY_UNAVAILABLE.Returns
Returns the created public key registration object with an assigned ID and active status.curl https://production.methodfi.com/teams/mle/public_keys \
-X POST \
-H "Method-Version: 2026-03-30" \
-H "Authorization: Bearer sk_WyZEWVfTcH7GqmPzUPk65Vjc" \
-H "Content-Type: application/json" \
-d '{
"type": "direct",
"contact": "security@yourcompany.com",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null
}'
const key = await method.teams.mle.publicKeys.create({
type: 'direct',
contact: 'security@yourcompany.com',
jwk: {
kid: 'your-unique-key-id',
kty: 'RSA',
alg: 'RSA-OAEP-256',
use: 'enc',
n: 's3C9N7Vz...J7c',
e: 'AQAB',
iat: 1780309800,
nbf: 1780309800,
exp: 1811845800
},
well_known_endpoint: null
});
key = method.teams.mle.public_keys.create({
'type': 'direct',
'contact': 'security@yourcompany.com',
'jwk': {
'kid': 'your-unique-key-id',
'kty': 'RSA',
'alg': 'RSA-OAEP-256',
'use': 'enc',
'n': 's3C9N7Vz...J7c',
'e': 'AQAB',
'iat': 1780309800,
'nbf': 1780309800,
'exp': 1811845800
},
'well_known_endpoint': None
})
{
"success": true,
"data": {
"id": "team_jwk_12345",
"type": "direct",
"jwk": {
"kid": "your-unique-key-id",
"kty": "RSA",
"alg": "RSA-OAEP-256",
"use": "enc",
"n": "s3C9N7Vz...J7c",
"e": "AQAB",
"iat": 1780309800,
"nbf": 1780309800,
"exp": 1811845800
},
"well_known_endpoint": null,
"status": "active",
"contact": "security@yourcompany.com",
"created_at": "2026-06-01T10:30:00Z",
"updated_at": "2026-06-01T10:30:00Z"
},
"message": null
}