Paycose Docs
Service AccountOptions
POST/service_accounts/{service_account_id}/roll_key

Roll Key

Rotate the API key pair for a service account.

Generates a new P-256 keypair, deletes the old Hydra OAuth2 client, and registers a new one with the new JWKS. Old publishable_key + secret_key are immediately invalidated. Any access tokens minted under the old client return active:false from Hydra introspection on the next API call. The new secret_key is shown ONCE in this response.

Integrator action required after roll: redeploy SDK builds with the new publishable_key (browser/mobile ECDH); update server-side env with the new secret_key.

Requires: Bearer token, X-Country header, AAL2. In live mode this also requires the application to be KYB verified.

Request

Example

curl -X POST 'https://api.paycose.com/api/v1/app1/platform/wallet/service_accounts/{{service_account_id}}/roll_key' \
  -H 'X-Session-Token: {{session_token}}' \
  -H 'X-Country: {{country}}' \
  -H 'X-Test-Mode: {{x_test_mode}}'

Headers

NameValueDescription
X-Session-Token{{session_token}}
X-Country{{country}}
X-Test-Mode{{x_test_mode}}true=wallet_test, false=wallet_live (default). Toggle the x_test_mode collection variable to flip every applicable request.

Responses

400400 Bad Request

Headers

NameValue
Content-Typeapplication/json

Body

{
  "object": "error",
  "code": "<string>",
  "key": "<string>",
  "i18n_key": "<string>",
  "message": "<string>",
  "request_id": "<string>"
}
500500 Internal Server Error

Headers

NameValue
Content-Typeapplication/json

Body

{
  "object": "error",
  "code": "<string>",
  "key": "<string>",
  "i18n_key": "<string>",
  "message": "<string>",
  "request_id": "<string>"
}

On this page