Skip to main content
Tombstoning marks a device as retired or compromised without erasing the fact that it once belonged to the DID. Compatible clients should ignore a tombstoned device for new delivery and key selection. Preserving the record helps other clients recognize old device references and avoid accidentally treating a retired identifier as new.

Tombstone or remove?

For a lost or compromised device, tombstoning is generally the safer public signal.

Request

string
required
The DID that owns the device.
string
required
The device identifier to tombstone.
The body is required and carries a DID-key proof with action tombstone_device, the current control_nonce, valid_until, signer_key_id, canonical_payload, and signature. See Authorize a Directory update.

Response

After settlement, resolve the DID and confirm that the matching device contains "tombstoned": true.

Straight to the point

  • DID-key proof body required
  • Operation: tombstone_device
  • Accepted: 202
  • Permanent removal uses DELETE /dids/{did}/devices/{deviceId}