> ## Documentation Index
> Fetch the complete documentation index at: https://docs.openpayload.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Update the root public key

> Update the root public key in a public OpenPayload DID document.

Update the root public key in a public OpenPayload DID document.

The root key is the identity's highest-authority public key in the Directory record. Rotate it only from a trusted environment and retain the new private key securely before submitting the change.

<Warning>
  Losing the private key corresponding to the new root public key can permanently prevent future root-authorized updates.
</Warning>

Read [Authorize a Directory update](/guides/authorization) before signing.

## Path parameters

<ParamField path="did" type="string" required>
  The DID to update.
</ParamField>

## Request body

<ParamField body="did" type="string" required>
  The DID to update. It must match the path.
</ParamField>

<ParamField body="action" type="string" required>
  The operation name. Use `UpdateRootPubkey`.
</ParamField>

<ParamField body="new_root_pubkey" type="string" required>
  The public new root pubkey value for this operation.
</ParamField>

<ParamField body="nonce" type="string" required>
  The request nonce.
</ParamField>

<ParamField body="valid_until" type="string" required>
  The authorization expiration time.
</ParamField>

<ParamField body="signer_key_id" type="string">
  The public signing-key identifier. Defaults to `root`.
</ParamField>

<ParamField body="canonical_payload" type="string" required>
  The payload supplied by an OpenPayload-compatible signer.
</ParamField>

<ParamField body="signature" type="string" required>
  The authorization signature.
</ParamField>

<RequestExample>
  ```bash Request theme={null}
  curl --request PUT \
    --url "https://directory.example.com/dids/did%3Aopenpayload%3A1111111111111111111111/root-pubkey" \
    --header "Content-Type: application/json" \
    --data '{
    "did": "did:openpayload:1111111111111111111111",
    "action": "UpdateRootPubkey",
    "new_root_pubkey": "<new-public-key>",
    "nonce": "<nonce>",
    "valid_until": "<future-epoch-milliseconds>",
    "signer_key_id": "root",
    "canonical_payload": "<payload>",
    "signature": "<signature>"
  }'
  ```
</RequestExample>

## Response

<ResponseField name="status" type="string" required>The submission status.</ResponseField>
<ResponseField name="did" type="string" required>The affected DID.</ResponseField>
<ResponseField name="action" type="string" required>The document operation.</ResponseField>
<ResponseField name="tx_hash" type="string" required>The transaction hash.</ResponseField>
<ResponseField name="message" type="string" required>A human-readable submission result.</ResponseField>

<ResponseExample>
  ```json 202 Response theme={null}
  {
    "status": "accepted",
    "did": "did:openpayload:1111111111111111111111",
    "action": "UpdateRootPubkey",
    "tx_hash": "<transaction-hash>",
    "message": "DID document modification submitted"
  }
  ```
</ResponseExample>

<Note>
  `202 Accepted` means the Directory accepted the request for processing. It does not confirm final settlement.
</Note>

## Straight to the point

* Action: `UpdateRootPubkey`
* New key: exactly 32-byte Ed25519 public key encoding
* Authorization: sign with a currently authorized key
* Store the new private key before submission


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.