curl --request PUT \
--url "https://directory.example.com/personas/example.com/controllers" \
--header "Content-Type: application/json" \
--data '{
"persona": "example.com",
"action": "rotate_persona_controllers",
"controller_keys": [
"did:openpayload:1111111111111111111111#keys-1",
"did:openpayload:1111111111111111111111#keys-2"
],
"controller_threshold": 1,
"nonce": "<operator-nonce>",
"valid_until": "<epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<encoded-scale-payload>",
"signature": "<base64-ed25519-signature>"
}'
Personas
Rotate Persona controllers
Replace the controller verification-method IDs authorized for Persona operations
curl --request PUT \
--url "https://directory.example.com/personas/example.com/controllers" \
--header "Content-Type: application/json" \
--data '{
"persona": "example.com",
"action": "rotate_persona_controllers",
"controller_keys": [
"did:openpayload:1111111111111111111111#keys-1",
"did:openpayload:1111111111111111111111#keys-2"
],
"controller_threshold": 1,
"nonce": "<operator-nonce>",
"valid_until": "<epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<encoded-scale-payload>",
"signature": "<base64-ed25519-signature>"
}'
Change a Persona’s controller keys using a signature from one currently authorized controller. Persona v1 requires
The signer must be in both the current and submitted controller sets. Every submitted controller must already exist as a signing key on the operator DID.
controller_threshold to equal 1; multi-signature threshold enforcement is reserved for a future contract.
Rotations are staged to prevent lockout: the key authorizing this request must remain in the submitted controller set. Add a new key first. After that transaction finalizes, the new key can authorize a later rotation that removes the previous key.
Request
string
required
Active registered Persona.
string[]
required
Between 1 and 8 unique signing-key IDs published by the operator DID. This set must include
signer_key_id.integer
required
Must equal
1 in Persona v1.curl --request PUT \
--url "https://directory.example.com/personas/example.com/controllers" \
--header "Content-Type: application/json" \
--data '{
"persona": "example.com",
"action": "rotate_persona_controllers",
"controller_keys": [
"did:openpayload:1111111111111111111111#keys-1",
"did:openpayload:1111111111111111111111#keys-2"
],
"controller_threshold": 1,
"nonce": "<operator-nonce>",
"valid_until": "<epoch-milliseconds>",
"signer_key_id": "did:openpayload:1111111111111111111111#keys-1",
"canonical_payload": "<encoded-scale-payload>",
"signature": "<base64-ed25519-signature>"
}'
Response
202 Response
{
"status": "accepted",
"persona": "example.com",
"extrinsic": "apply_persona_with_proof",
"operation": "rotate_persona_controllers",
"tx_hash": "<transaction-hash>"
}
Straight to the point
PUT /personas/{persona}/controllers
- Action:
rotate_persona_controllers - Authorization: one current Persona controller
- Staging: the authorizing key remains until a later rotation
- Persona v1 threshold: exactly
1 - Accepted submission:
202

