> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# client.credentials

> Short-lived JWT credential issuance and revocation.

Short-lived JWT credential issuance and revocation.

Reach it as `client.credentials` on a [`QumoClient`](/sdk/reference/client#qumoclient).

### issue

```ts theme={null}
issue(params: IssueCredentialParams): Promise<IssuedCredential>
```

Direct machine issuance: the client must authenticate with the raw API
key (Bearer) — a console session cannot call this route.

Types: [`IssueCredentialParams`](/sdk/reference/types#issuecredentialparams), [`IssuedCredential`](/sdk/reference/types#issuedcredential)

### issueForProject

```ts theme={null}
issueForProject(projectId: string, params: IssueForProjectParams): Promise<IssuedCredential>
```

Console issuance on behalf of a project API key: the session-authenticated
route. The token is minted under the key's authority (broadcast
path, mode, scopes); the key's secret is never needed.

Types: [`IssueForProjectParams`](/sdk/reference/types#issueforprojectparams), [`IssuedCredential`](/sdk/reference/types#issuedcredential)

### revoke

```ts theme={null}
revoke(jti: string): Promise<void>
```

Revokes a credential by its `jti`; relays reject it from then on.

### getJWKS

```ts theme={null}
getJWKS(): Promise<JSONWebKeySet>
```

The public Ed25519 keys that verify relay credentials, active key first.
Public — no auth required. A relay you run yourself (a `dev` project)
verifies credentials against this set.

Types: [`JSONWebKeySet`](/sdk/reference/types#jsonwebkeyset)
