Skip to main content
Update the root public key in a public OpenPayload DID document. The root key is the identity’s highest-authority public key in the Directory record. Rotate it only from a trusted environment and retain the new private key securely before submitting the change.
Losing the private key corresponding to the new root public key can permanently prevent future root-authorized updates.
Read Authorize a Directory update before signing.

Path parameters

string
required
The DID to update.

Request body

string
required
The DID to update. It must match the path.
string
required
The operation name. Use UpdateRootPubkey.
string
required
The public new root pubkey value for this operation.
string
required
The request nonce.
string
required
The authorization expiration time.
string
The public signing-key identifier. Defaults to root.
string
required
The payload supplied by an OpenPayload-compatible signer.
string
required
The authorization signature.

Response

string
required
The submission status.
string
required
The affected DID.
string
required
The document operation.
string
required
The transaction hash.
string
required
A human-readable submission result.
202 Accepted means the Directory accepted the request for processing. It does not confirm final settlement.

Straight to the point

  • Action: UpdateRootPubkey
  • New key: exactly 32-byte Ed25519 public key encoding
  • Authorization: sign with a currently authorized key
  • Store the new private key before submission