curl --request PUT \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/root-pubkey" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"new_root_pubkey": "<new-public-key>",
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "root",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
DID documents
Update the root public key
Update the root public key in a public OpenPayload DID document.
curl --request PUT \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/root-pubkey" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"new_root_pubkey": "<new-public-key>",
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "root",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
Update the root public key in a public OpenPayload DID document.
The root key is the identity’s highest-authority public key in the Directory record. Rotate it only from a trusted environment and retain the new private key securely before submitting the change.
Read Authorize a Directory update before signing.
Losing the private key corresponding to the new root public key can permanently prevent future root-authorized updates.
Path parameters
string
required
The DID to update.
Request body
string
required
The DID to update. It must match the path.
string
required
The operation name. Use
UpdateRootPubkey.string
required
The public new root pubkey value for this operation.
string
required
The request nonce.
string
required
The authorization expiration time.
string
The public signing-key identifier. Defaults to
root.string
required
The payload supplied by an OpenPayload-compatible signer.
string
required
The authorization signature.
curl --request PUT \
--url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/root-pubkey" \
--header "Content-Type: application/json" \
--data '{
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"new_root_pubkey": "<new-public-key>",
"nonce": "<nonce>",
"valid_until": "<future-epoch-milliseconds>",
"signer_key_id": "root",
"canonical_payload": "<payload>",
"signature": "<signature>"
}'
Response
string
required
The submission status.
string
required
The affected DID.
string
required
The document operation.
string
required
The transaction hash.
string
required
A human-readable submission result.
{
"status": "accepted",
"did": "did:openpayload:1111111111111111111111",
"action": "UpdateRootPubkey",
"tx_hash": "<transaction-hash>",
"message": "DID document modification submitted"
}
202 Accepted means the Directory accepted the request for processing. It does not confirm final settlement.Straight to the point
- Action:
UpdateRootPubkey - New key: exactly 32-byte Ed25519 public key encoding
- Authorization: sign with a currently authorized key
- Store the new private key before submission

