> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Relay Credential Verification Keys

> The Ed25519 public keys that verify relay credentials, as a JSON Web Key Set, active key first. A credential names its key in the JWS header's `kid`, the key's RFC 7638 thumbprint. During a key rotation the previous key stays listed until the credentials it signed have expired. Public and unauthenticated; cacheable for five minutes.



## OpenAPI

````yaml /api-reference/openapi.yaml get /v1/credentials/jwks
openapi: 3.1.0
info:
  title: Qumo Deploy REST API
  description: >
    The Qumo Deploy REST API provides programmatic control over edge relay
    clusters,

    ephemeral Relay Credential issuance, tenant lifecycle, machine identities,
    and billing.

    Authentication is operation-specific: Relay Keys authenticate relay access
    operations,

    while user sessions and Identity Tokens authenticate control-plane
    operations.
  version: 1.0.0
servers:
  - url: https://api.qumo-deploy.com
    description: Production Control Plane
  - url: http://localhost:8080
    description: Local Development / Sandbox
security:
  - BearerAuth: []
paths:
  /v1/credentials/jwks:
    get:
      summary: Relay Credential Verification Keys
      description: >-
        The Ed25519 public keys that verify relay credentials, as a JSON Web Key
        Set, active key first. A credential names its key in the JWS header's
        `kid`, the key's RFC 7638 thumbprint. During a key rotation the previous
        key stays listed until the credentials it signed have expired. Public
        and unauthenticated; cacheable for five minutes.
      responses:
        '200':
          description: JSON Web Key Set
          headers:
            Cache-Control:
              schema:
                type: string
                example: public, max-age=300
          content:
            application/json:
              schema:
                type: object
                required:
                  - keys
                properties:
                  keys:
                    type: array
                    items:
                      type: object
                      required:
                        - kty
                        - crv
                        - x
                        - kid
                        - alg
                        - use
                      properties:
                        kty:
                          type: string
                          enum:
                            - OKP
                        crv:
                          type: string
                          enum:
                            - Ed25519
                        x:
                          type: string
                          description: Public key, base64url without padding.
                        kid:
                          type: string
                          description: RFC 7638 JWK thumbprint of the key.
                        alg:
                          type: string
                          enum:
                            - EdDSA
                        use:
                          type: string
                          enum:
                            - sig
      security: []
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: SessionOrIdentityToken
      description: |
        User session or Identity Token. Relay Keys are not accepted.

````