Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Import a licence key

Imports an existing Ed25519 key (PKCS8), for a key already pinned in shipped clients.

Imports an existing Ed25519 key (PKCS8), for a key already pinned in shipped clients. Refused unless the expected public key is the imported key's public half.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys:import
  • Scope billing:licence_keys.approve
  • Effect write — a successful call changes state.
  • Collection licence_keys

#Request

FieldTypeWhat it is
parentstringThe environment the key belongs to. Required.
licence_key_idstringThe key's id; as on GenerateLicenceKeyRequest. Required. Required.
private_key_pkcs8bytesThe Ed25519 private key as PKCS8 DER in standard base64. Write-only: sealed on import, never returned. Required. Never returned again.
expected_public_keystringThe public key shipped clients pin, raw base64url without padding. The import is refused unless it is the public half of the imported key. Required.
specLicenceKeySpecShown to operators.

#LicenceKeySpec

FieldTypeWhat it is
descriptionstringShown to operators.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/licence_keys/{licence_key}.
uidstringlkey_<cell><ulid>; never reused. The keyless public export is addressed by it. Output only.
metaResourceMetaResource metadata.
specLicenceKeySpecDesired state. Required.
statusLicenceKeyStatusObserved state. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#LicenceKeySpec

FieldTypeWhat it is
descriptionstringShown to operators.

#LicenceKeyStatus

FieldTypeWhat it is
observed_generationint64The generation this status was computed from. Output only.
conditionsCondition[]Ready while the key exists. Output only.
statestringactive signs new terms; retired signs only terms already frozen to it and stays exported for verification. Output only.
originstringgenerated or imported. Output only.
public_keystringThe raw Ed25519 public key, base64url without padding. Output only.
retire_timetimestampWhen the key was retired. Output only.

#Condition

FieldTypeWhat it is
typestringThe condition type, for example Ready.
statusConditionStatusWhether the condition holds. One of true, false, unknown.
observed_generationint64The generation this observation was made against.
reasonstringA machine-readable UpperCamelCase reason.
messagestringA customer-safe human-readable message.
severitySeverityHow severe a FALSE condition is. One of info, warning, error.
transition_timetimestampWhen status last changed.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/licence_keys:import" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"expected_public_key":"…","licence_key_id":"…","private_key_pkcs8":"…"}'