v16

OpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-04-0886158866.0 KB
Hardware Security Key

Create Security Key

post/api/{serviceId}/hsk/create

Path parameters

serviceIdstring required

A service ID.

Request body

ktystring

The key type (EC or RSA)

usestring

The key on the HSM. When the key use is "sig" (signature), the private key on the HSM is used to sign data and the corresponding public key is used to verify the signature. When the key use is "enc" (encryption), the private key on the HSM is used to decrypt encrypted data which have been encrypted with the corresponding public key

kidstring

Key ID for the key on the HSM.

hsmNamestring

The name of the HSM. The identifier for the HSM that sits behind the Authlete server. For example, "google".

algstring

The algorithm of the key on the HSM. When the key use is "sig", the algorithm represents a signing algorithm such as "ES256". When the key use is "enc", the algorithm represents an encryption algorithm such as "RSA-OAEP-256".

It is rare that HSMs support all the algorithms listed in RFC 7518 JSON Web Algorithms (JWA). When the specified algorithm is not supported by the HSM, the request to the /hsk/create API fails.

Response

HSK created successfully

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

action'SUCCESS' | 'INVALID_REQUEST' | 'NOT_FOUND' | 'SERVER_ERROR'

Result of the API call.