---
# @generated by sylphx-gen 0.1.0 from contracts@9f583d0fafbf9813b0da162eef18cd95767f9a68d1de3edf29cf2143c78b11fb. Do not edit.
title: "Licence keys"
description: "The `licence_keys` collection of Sylphx Money: A Licence Key is one Ed25519 signing key Money holds for an environment."
type: reference
product: payments
summary: "A Licence Key is one Ed25519 signing key Money holds for an environment."
updated: 2026-09-28
order: 900
---

A Licence Key is one Ed25519 signing key Money holds for an environment. The private half is generated here (or imported once, for a key already pinned in shipped clients), sealed with Money's seal keys, and never returned or logged. The public half is exported keyless at `GET /v1/money/licence_keys/{uid}`, in the raw base64url form a client pins.

**Service** Sylphx Money · **Resource type** `money.sylphx.com/LicenceKey` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/licence_keys/{licence_key}` · **Shape** `spec_status`

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/licence_keys/{licence_key}`. |
| `uid` | `string` | `lkey_<cell><ulid>`; never reused. The keyless public export is addressed by it. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `LicenceKeySpec` | Desired state. Required. |
| `status` | `LicenceKeyStatus` | Observed state. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `POST` | [`generate`](/docs/api/licence_keys#generate) | Generates a licence key: Money creates the Ed25519 key, seals it, and never returns the private half. Needs the approval-class scope, which the developer role does not hold. |
| `POST` | [`import`](/docs/api/licence_keys#import) | Imports an existing Ed25519 key (PKCS8), for a key already pinned in shipped clients. Refused unless the expected public key is the imported key's public half. |
| `POST` | [`retire`](/docs/api/licence_keys#retire) | Retires a licence key: it stops signing new terms and stays exported for verification. |
| `GET` | [`get`](/docs/api/licence_keys#get) | Gets a licence key (its public half, never the private). |
| `GET` | [`list`](/docs/api/licence_keys#list) | Lists licence keys, newest first. |

## generate

Generates a licence key: Money creates the Ed25519 key, seals it, and never returns the private half. Needs the approval-class scope, which the developer role does not hold.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys:generate` · scope `billing:licence_keys.approve` · effect `write` · [Request, response and examples](/docs/api/licence_keys/generate)

## import

Imports an existing Ed25519 key (PKCS8), for a key already pinned in shipped clients. Refused unless the expected public key is the imported key's public half.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys:import` · scope `billing:licence_keys.approve` · effect `write` · [Request, response and examples](/docs/api/licence_keys/import)

## retire

Retires a licence key: it stops signing new terms and stays exported for verification.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys/licence-key:retire` · scope `billing:licence_keys.approve` · effect `write` · [Request, response and examples](/docs/api/licence_keys/retire)

## get

Gets a licence key (its public half, never the private).

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys/licence-key` · scope `billing:read` · effect `read` · [Request, response and examples](/docs/api/licence_keys/get)

## list

Lists licence keys, newest first.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys` · scope `billing:read` · effect `read` · paginated · [Request, response and examples](/docs/api/licence_keys/list)
