Skip to main content
Short-lived JWT credential issuance and revocation. Reach it as client.credentials on a QumoClient.

issue

Direct machine issuance: the client must authenticate with the raw API key (Bearer) — a console session cannot call this route. Types: IssueCredentialParams, IssuedCredential

issueForProject

Console issuance on behalf of a project API key: the session-authenticated route. The token is minted under the key’s authority (broadcast path, mode, scopes); the key’s secret is never needed. Types: IssueForProjectParams, IssuedCredential

revoke

Revokes a credential by its jti; relays reject it from then on.

getJWKS

The public Ed25519 keys that verify relay credentials, active key first. Public — no auth required. A relay you run yourself (a dev project) verifies credentials against this set. Types: JSONWebKeySet