curl -sS -X POST "https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/did:ocss:loopline/payload-key" \
-H "Content-Type: application/json" \
-d '{
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}'const BASE = "https://phosra-api-sandbox-production.up.railway.app/api/v1";
const res = await fetch(`${BASE}/advisors/did:ocss:loopline/payload-key`, {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}),
});
console.log(res.status, await res.json());
import requests
BASE = "https://phosra-api-sandbox-production.up.railway.app/api/v1"
res = requests.post(
f"{BASE}/advisors/did:ocss:loopline/payload-key",
json={
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
},
)
print(res.status_code, res.json())
package main
import (
"bytes"
"fmt"
"io"
"net/http"
)
func main() {
base := "https://phosra-api-sandbox-production.up.railway.app/api/v1"
body := bytes.NewBufferString(`{
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}`)
req, _ := http.NewRequest("POST", base+"/advisors/did:ocss:loopline/payload-key", body)
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
out, _ := io.ReadAll(resp.Body)
fmt.Println(resp.Status, string(out))
}
<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'payload_public_key_jwk' => '<string>',
'sig' => '<string>',
'issued_at' => '2023-11-07T05:31:56Z'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"payload_public_key_jwk\": \"<string>\",\n \"sig\": \"<string>\",\n \"issued_at\": \"2023-11-07T05:31:56Z\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"payload_public_key_jwk\": \"<string>\",\n \"sig\": \"<string>\",\n \"issued_at\": \"2023-11-07T05:31:56Z\"\n}"
response = http.request(request)
puts response.read_body{
"advisor_id": "7e4c1a90-3b28-4d67-95f1-0a8c6b2e9d43",
"payload_key_kid": "did:ocss:touchstone#payload-2026-07",
"status": "declared"
}{
"error": "Bad Request",
"message": "payload_public_key_jwk is required (clearing a declared key is not self-service)",
"code": 400
}{
"error": "Unauthorized",
"message": "declaration signature invalid or stale",
"code": 401
}{
"error": "Forbidden",
"message": "advisor is revoked",
"code": 403
}{
"error": "Not Found",
"message": "advisor not found",
"code": 404
}{
"error": "Request Entity Too Large",
"message": "request body exceeds the declaration size bound",
"code": 413
}{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}Declare payload key
Self-service possession-auth declaration. Authentication is by the advisor’s registered Ed25519 signing key: the body must carry a detached signature over the v2 declaration preimage (ocss-payload-key-declaration-v2), not the bare JWK bytes. The preimage is these five fields newline-joined, in order: the literal scheme string ocss-payload-key-declaration-v2; the advisor’s UUID; the advisor’s registered signing key_id; issued_at rendered as RFC3339 UTC truncated to the second; and the raw payload_public_key_jwk bytes (last, no trailing newline). Domain-separating the scheme, binding the advisor UUID + signing key_id, and time-bounding issued_at (±5 minutes of the server clock) together rule out a captured v1-style signature, a declaration replayed later, and a declaration replayed against a different advisor. No bearer token scheme applies to this operation — authorization is established by possession of the registered private key. Clearing a declared key is not self-service — use the admin revoke flow.
curl -sS -X POST "https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/did:ocss:loopline/payload-key" \
-H "Content-Type: application/json" \
-d '{
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}'const BASE = "https://phosra-api-sandbox-production.up.railway.app/api/v1";
const res = await fetch(`${BASE}/advisors/did:ocss:loopline/payload-key`, {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}),
});
console.log(res.status, await res.json());
import requests
BASE = "https://phosra-api-sandbox-production.up.railway.app/api/v1"
res = requests.post(
f"{BASE}/advisors/did:ocss:loopline/payload-key",
json={
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
},
)
print(res.status_code, res.json())
package main
import (
"bytes"
"fmt"
"io"
"net/http"
)
func main() {
base := "https://phosra-api-sandbox-production.up.railway.app/api/v1"
body := bytes.NewBufferString(`{
"payload_public_key_jwk": "{\"kty\":\"EC\",\"crv\":\"P-256\",\"x\":\"...\",\"y\":\"...\"}",
"sig": "base64url-ed25519-signature-over-the-v2-preimage",
"issued_at": "2026-07-06T14:30:00Z"
}`)
req, _ := http.NewRequest("POST", base+"/advisors/did:ocss:loopline/payload-key", body)
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
out, _ := io.ReadAll(resp.Body)
fmt.Println(resp.Status, string(out))
}
<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'payload_public_key_jwk' => '<string>',
'sig' => '<string>',
'issued_at' => '2023-11-07T05:31:56Z'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}HttpResponse<String> response = Unirest.post("https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"payload_public_key_jwk\": \"<string>\",\n \"sig\": \"<string>\",\n \"issued_at\": \"2023-11-07T05:31:56Z\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/api/v1/advisors/{id}/payload-key")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"payload_public_key_jwk\": \"<string>\",\n \"sig\": \"<string>\",\n \"issued_at\": \"2023-11-07T05:31:56Z\"\n}"
response = http.request(request)
puts response.read_body{
"advisor_id": "7e4c1a90-3b28-4d67-95f1-0a8c6b2e9d43",
"payload_key_kid": "did:ocss:touchstone#payload-2026-07",
"status": "declared"
}{
"error": "Bad Request",
"message": "payload_public_key_jwk is required (clearing a declared key is not self-service)",
"code": 400
}{
"error": "Unauthorized",
"message": "declaration signature invalid or stale",
"code": 401
}{
"error": "Forbidden",
"message": "advisor is revoked",
"code": 403
}{
"error": "Not Found",
"message": "advisor not found",
"code": 404
}{
"error": "Request Entity Too Large",
"message": "request body exceeds the declaration size bound",
"code": 413
}{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Advisor agent ID.
Body
Serialized EC P-256 public JWK (≤4 KiB). The kid must form a valid did#kid distinct from the advisor's signing key_id.
Detached Ed25519 signature over the v2 preimage — NOT the bare JWK bytes. Build it as five newline-joined fields: the scheme string ocss-payload-key-declaration-v2, the advisor UUID, the advisor's registered signing key_id, issued_at (RFC3339 UTC, truncated to the second), and the raw payload_public_key_jwk bytes — then sign with the advisor's registered private key.
RFC3339 timestamp of this declaration — also one of the signed preimage fields (freshness-bound to ±5 minutes of the server clock; stale or future-dated declarations are rejected).