> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# client.signingKeys

> Signing keys — the Ed25519 keys your app signs relay credentials with.

Signing keys — the Ed25519 keys your app signs relay credentials with. Your
app keeps the private key; qumo stores the public key, confined to a prefix
under the project's root (`<workspace slug>/<project slug>`).

Reach it as `client.signingKeys` on a [`QumoClient`](/sdk/reference/client#qumoclient).

### list

```ts theme={null}
list(projectId: string): Promise<SigningKey[]>
```

Lists a project's signing keys, newest first, revoked ones included.

Types: [`SigningKey`](/sdk/reference/types#signingkey)

### create

```ts theme={null}
create(projectId: string, params: { name: string; prefix?: string }): Promise<CreatedSigningKey>
```

Generates an Ed25519 signing key in this process (Web Crypto) and
registers its public half, in one call. Returns the registered key and
the private key, which exists nowhere else: store it on your app's
server. `prefix` narrows the project root; omit it to confine the key to
the whole project. If registration fails, the generated key is discarded.

Types: [`CreatedSigningKey`](/sdk/reference/types#createdsigningkey)

### register

```ts theme={null}
register(projectId: string, params: { name: string; privateKey: Ed25519PrivateJWK; prefix?: string }): Promise<SigningKey>
```

Registers the public half of `privateKey`, such as the file
`qumo auth keygen` writes. It proves you hold the private key by signing
a dated message with it locally (Web Crypto), and sends only the public
key and the signature: the private key never leaves this process.
`prefix` narrows the project root; omit it to confine the key to the
whole project.

Types: [`Ed25519PrivateJWK`](/sdk/reference/types#ed25519privatejwk), [`SigningKey`](/sdk/reference/types#signingkey)

### registerSigned

```ts theme={null}
registerSigned(projectId: string, params: { name: string; public_key: Ed25519PublicJWK; signed_at: number; signature: string; prefix?: string }): Promise<SigningKey>
```

Registers a public key with a signature made elsewhere, for when the
private key lives where this code doesn't run (an HSM, another service).
`signature` is the Ed25519 signature, base64url without padding, over
`qumo-signing-key-registration:<projectId>:<signed_at>`, where `signed_at`
is the current time in unix seconds (accepted within five minutes).

Types: [`Ed25519PublicJWK`](/sdk/reference/types#ed25519publicjwk), [`SigningKey`](/sdk/reference/types#signingkey)

### revoke

```ts theme={null}
revoke(projectId: string, kid: string): Promise<SigningKey>
```

Revokes a key: managed relays stop trusting it, which ends its live
sessions within about a minute. Final. To rotate without interrupting
anyone, sign with a new key and revoke the old one an hour later, once
its last credential has expired.

Types: [`SigningKey`](/sdk/reference/types#signingkey)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.