> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bastion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register Signing Key

> Register a device signing key for a given identity



## OpenAPI

````yaml /v2/openapi.yaml post /v2/identities/{identity_id}/signing-keys
openapi: 3.1.0
info:
  title: Bastion APIs
  version: '2.0'
servers:
  - url: https://api.prod.bastion.com
    description: Production environment
  - url: https://api.sandbox.bastion.io
    description: Sandbox environment
security:
  - auth: []
tags:
  - name: Bastion APIs
paths:
  /v2/identities/{identity_id}/signing-keys:
    post:
      tags:
        - Signing Keys
      summary: Register Signing Key
      description: Register a device signing key for a given identity
      operationId: bastion.api.v2.API.RegisterSigningKey
      parameters:
        - name: identity_id
          in: path
          required: true
          schema:
            type: string
            title: identity_id
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                identity_id:
                  type: string
                  title: identity_id
                public_key:
                  $ref: '#/components/schemas/bastion.common.JwkEcPublicKey'
                  title: public_key
                label:
                  type: string
                  title: label
                  description: '(OPTIONAL) '
              title: RegisterSigningKeyRequest
              additionalProperties: false
        required: true
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/bastion.api.v2.RegisterSigningKeyResponse'
        '400':
          description: Bad request
        '409':
          description: Resource Conflicts
        '500':
          description: Internal Server Error
components:
  schemas:
    bastion.common.JwkEcPublicKey:
      type: object
      properties:
        kid:
          type: string
          title: kid
          description: '(OPTIONAL) '
        kty:
          type: string
          title: kty
        crv:
          type: string
          title: crv
        x:
          type: string
          title: x
        'y':
          type: string
          title: 'y'
      title: JwkEcPublicKey
      required:
        - kty
        - crv
        - x
        - 'y'
      additionalProperties: false
    bastion.api.v2.RegisterSigningKeyResponse:
      type: object
      properties:
        signing_key:
          $ref: '#/components/schemas/bastion.api.v2.SigningKey'
          title: signing_key
      title: RegisterSigningKeyResponse
      additionalProperties: false
    bastion.api.v2.SigningKey:
      type: object
      properties:
        key_id:
          type: string
          title: key_id
        identity_id:
          type: string
          title: identity_id
        public_key:
          $ref: '#/components/schemas/bastion.common.JwkEcPublicKey'
          title: public_key
        label:
          type: string
          title: label
        created_at:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: created_at
      title: SigningKey
      additionalProperties: false
    google.protobuf.Timestamp:
      type: string
      examples:
        - '2023-01-15T01:30:15.01Z'
        - '2024-12-25T12:00:00Z'
      format: date-time
      description: >-
        A Timestamp represents a point in time independent of any time zone or
        local
         calendar, encoded as a count of seconds and fractions of seconds at
         nanosecond resolution. The count is relative to an epoch at UTC midnight on
         January 1, 1970, in the proleptic Gregorian calendar which extends the
         Gregorian calendar backwards to year one.

         All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap
         second table is needed for interpretation, using a [24-hour linear
         smear](https://developers.google.com/time/smear).

         The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By
         restricting to that range, we ensure that we can convert to and from [RFC
         3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.

         # Examples

         Example 1: Compute Timestamp from POSIX `time()`.

             Timestamp timestamp;
             timestamp.set_seconds(time(NULL));
             timestamp.set_nanos(0);

         Example 2: Compute Timestamp from POSIX `gettimeofday()`.

             struct timeval tv;
             gettimeofday(&tv, NULL);

             Timestamp timestamp;
             timestamp.set_seconds(tv.tv_sec);
             timestamp.set_nanos(tv.tv_usec * 1000);

         Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.

             FILETIME ft;
             GetSystemTimeAsFileTime(&ft);
             UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

             // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
             // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
             Timestamp timestamp;
             timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
             timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

         Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.

             long millis = System.currentTimeMillis();

             Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
                 .setNanos((int) ((millis % 1000) * 1000000)).build();

         Example 5: Compute Timestamp from Java `Instant.now()`.

             Instant now = Instant.now();

             Timestamp timestamp =
                 Timestamp.newBuilder().setSeconds(now.getEpochSecond())
                     .setNanos(now.getNano()).build();

         Example 6: Compute Timestamp from current time in Python.

             timestamp = Timestamp()
             timestamp.GetCurrentTime()

         # JSON Mapping

         In JSON format, the Timestamp type is encoded as a string in the
         [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the
         format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z"
         where {year} is always expressed using four digits while {month}, {day},
         {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional
         seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),
         are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone
         is required. A ProtoJSON serializer should always use UTC (as indicated by
         "Z") when printing the Timestamp type and a ProtoJSON parser should be
         able to accept both UTC and other timezones (as indicated by an offset).

         For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past
         01:30 UTC on January 15, 2017.

         In JavaScript, one can convert a Date object to this format using the
         standard
         [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)
         method. In Python, a standard `datetime.datetime` object can be converted
         to this format using
         [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with
         the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use
         the Joda Time's [`ISODateTimeFormat.dateTime()`](
         http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()
         ) to obtain a formatter capable of generating timestamps in this format.
  securitySchemes:
    auth:
      type: http
      description: Bearer authentication with an API token
      scheme: bearer

````

## Related topics

- [Delete Signing Key](/v2/api-reference/signing-keys/delete-signing-key.md)
- [List Signing Keys](/v2/api-reference/signing-keys/list-signing-keys.md)
- [Rotate Webhook Signing Key](/v2/api-reference/webhooks/rotate-webhook-signing-key.md)
- [Security architecture overview](/guides/security/overview.md)
- [Request signing with JWTs](/v2/api-reference/authentication/request-signing.md)
