Skip to main content
POST
Creates a new public key registration for Message Level Encryption. You can register your key using either direct registration (providing the JWK directly) or well-known endpoint registration (providing a URL where Method can fetch your JWKS). Both encryption keys (use: "enc") and signing keys (use: "sig") may be registered. Encryption keys are used to encrypt responses to you. Signing keys are used to verify the signature on your requests on the signed MLE path.
Each key ID (kid) can only be registered once. Choose either direct or well-known registration for each unique key.

Body

Well-Known Endpoint Requirements

If using type: "well_known", your endpoint must return a JWKS that meets these requirements:
  1. The document must have a top-level field named keys that has a list as its value.
  2. Each JWK (an item in the list of keys) must be an object with a field named kty equal to RSA, a field n that is a valid string n for a JWK in accordance with the RFC, and a field e that is a valid string e for a JWK in accordance with the RFC.
  3. Each JWK must have a field kid and it must be a string. Keys without a kid are dropped. On the standard MLE path, this value is what you pass as cid when making requests to Method.
  4. use is optional and defaults to enc. Both enc and sig are accepted.
  5. alg is optional. If present, it must match the use: RSA-OAEP-256 for enc, and RS256 for sig. A key whose alg does not match its use is dropped.
  6. iat, nbf, and exp are optional numeric claims. Method preserves them and uses them for key selection and validity checks.
A single well-known endpoint can serve both your encryption key and your signing key. A team may also use direct registration and a well-known endpoint together, provided each kid is registered through only one of the two mechanisms, as described in the note above.

Registering a Signing Key

The signed MLE path requires a signing key in addition to an encryption key. Register it with use: "sig" and alg: "RS256":
Register an iat on every encryption key if more than one will ever be active at a time: on the signed MLE path Method selects the response encryption key by the highest iat among in-window keys, and a tie with no iat fails with MLE_ENCRYPTION_KEY_UNAVAILABLE.

Returns

Returns the created public key registration object with an assigned ID and active status.