curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/devices/mobile-01/tombstone" \
--header "Content-Type: application/json" \
--data '{"did":"did:openpayload:1111111111111111111111","device_id":"mobile-01","action":"tombstone_device","nonce":"<control_nonce>","valid_until":"<epoch-millis>","signer_key_id":"<authorized-key-id>","canonical_payload":"<payload>","signature":"<signature>"}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"extrinsic": "apply_control_with_proof",
"tx_hash": "<transaction-hash>",
"message": "Chain extrinsic submitted"
}
DIDs
Tombstone a device
Retire a device while preserving a public record that it must no longer be trusted
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/devices/mobile-01/tombstone" \
--header "Content-Type: application/json" \
--data '{"did":"did:openpayload:1111111111111111111111","device_id":"mobile-01","action":"tombstone_device","nonce":"<control_nonce>","valid_until":"<epoch-millis>","signer_key_id":"<authorized-key-id>","canonical_payload":"<payload>","signature":"<signature>"}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"extrinsic": "apply_control_with_proof",
"tx_hash": "<transaction-hash>",
"message": "Chain extrinsic submitted"
}
Tombstoning marks a device as retired or compromised without erasing the fact that it once belonged to the DID.
Compatible clients should ignore a tombstoned device for new delivery and key selection. Preserving the record helps other clients recognize old device references and avoid accidentally treating a retired identifier as new.
For a lost or compromised device, tombstoning is generally the safer public signal.
The body is required and carries a DID-key proof with action
After settlement, resolve the DID and confirm that the matching device contains
Tombstone or remove?
| Choice | Result |
|---|---|
| Tombstone | Keeps the device in the public record with tombstoned: true |
| Remove | Uses the separate DELETE route and removes the active entry |
Request
string
required
The DID that owns the device.
string
required
The device identifier to tombstone.
tombstone_device, the current control_nonce,
valid_until, signer_key_id, canonical_payload, and signature. See
Authorize a Directory update.
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/devices/mobile-01/tombstone" \
--header "Content-Type: application/json" \
--data '{"did":"did:openpayload:1111111111111111111111","device_id":"mobile-01","action":"tombstone_device","nonce":"<control_nonce>","valid_until":"<epoch-millis>","signer_key_id":"<authorized-key-id>","canonical_payload":"<payload>","signature":"<signature>"}'
Response
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"extrinsic": "apply_control_with_proof",
"tx_hash": "<transaction-hash>",
"message": "Chain extrinsic submitted"
}
"tombstoned": true.
Straight to the point
POST /dids/{did}/devices/{deviceId}/tombstone
- DID-key proof body required
- Operation:
tombstone_device - Accepted:
202 - Permanent removal uses
DELETE /dids/{did}/devices/{deviceId}

