curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#relay",
"type": "OpenPayloadRelayService",
"serviceEndpoint": ["https://relay.example.com"]
},
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#cache",
"type": "OpenPayloadCacheService",
"serviceEndpoint": ["https://cache.example.com"],
"authorization": [
"did:openpayload:1111111111111111111111#keys-1"
]
},
"nonce": "<next-nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
DID documents
Add a DID service
Add a DID service in a public OpenPayload DID document.
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#relay",
"type": "OpenPayloadRelayService",
"serviceEndpoint": ["https://relay.example.com"]
},
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#cache",
"type": "OpenPayloadCacheService",
"serviceEndpoint": ["https://cache.example.com"],
"authorization": [
"did:openpayload:1111111111111111111111#keys-1"
]
},
"nonce": "<next-nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
A DID service tells compatible clients where or how an identity can be reached. For example, it can advertise a Relay, Cache, or Archive endpoint.
This is an authorized public-state change. Read Authorize a Directory update before constructing
When a delivery policy references this service, every endpoint must be a public HTTPS base URI without credentials, a query string, or a fragment. Localhost, local/internal names, and known non-public or special-use IP literals are not valid policy route targets.
Each service is a separate mutation and consumes the current
canonical_payload.
Path parameters
string
required
The DID to update.
Request body
string
required
The DID to update. It must match the path.
string
required
The operation name. Use
AddService.object
required
The public service value for this operation.
string
required
The complete DID URL for this service, such as
did:openpayload:...#relay, did:openpayload:...#cache, or did:openpayload:...#archive.string
required
Use
OpenPayloadRelayService for Forward policy steps, OpenPayloadCacheService for Store, or OpenPayloadArchiveService for Archive. A single physical endpoint can be published under separate service IDs when it supports both Cache and Archive roles.string | string[]
required
One URI or an array of URIs. Responses use the canonical array form.
string[]
DID URL references to verification methods allowed to authorize use of the service. Include this for
OpenPayloadCacheService so recipients can prove retrieval and acknowledgement access. An Archive entry does not replace the Cache entry used for those proofs.integer
Optional non-negative
u32 priority.string
required
The request nonce.
string
required
The authorization expiration time.
string
The public signing-key identifier. Defaults to
root.string
required
The payload supplied by an OpenPayload-compatible signer.
string
required
The authorization signature.
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#relay",
"type": "OpenPayloadRelayService",
"serviceEndpoint": ["https://relay.example.com"]
},
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
curl --request POST \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/document/services" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"service": {
"id": "did:openpayload:1111111111111111111111#cache",
"type": "OpenPayloadCacheService",
"serviceEndpoint": ["https://cache.example.com"],
"authorization": [
"did:openpayload:1111111111111111111111#keys-1"
]
},
"nonce": "<next-nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
document_nonce. Fetch the nonce again, rebuild the canonical payload, and sign it before submitting the second service.
Response
string
required
The submission status.
string
required
The affected DID.
string
required
The document operation.
string
required
The transaction hash.
string
required
A human-readable submission result.
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "AddService",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
202 Accepted means the Directory accepted the request for processing. It does not confirm final settlement.Straight to the point
- Action:
AddService - Canonical item: the complete service object
- Nonce domain: DID document
- Accepted payload encoding:
0xhex or Base64 SCALE bytes
Complete messaging DID document
See both services in context with the verification and key-agreement methods they depend on.

