Skip to main content
POST
Create a delegated signing key

Authorizations

Authorization
string
header
required

API token authentication using format <api token id>:<api client secret>

Headers

Grid-Wallet-Signature
string

Full API-key stamp built over the prior payloadToSign with the session API keypair of a verified credential on the same internal account. Required on the signed retries; ignored on the initial call.

Request-Id
string

The requestId returned in the prior 202 response, echoed back exactly on the signed retry so the server can correlate it with the issued challenge. Required on the signed retries; must be paired with Grid-Wallet-Signature.

Body

application/json

Creates a delegated signing key for a card funding source or an agent. Exactly one of cardId or agentId is required. Requests that provide both fields or neither field return a 400 response.

internalAccountId
string
required

The id of the Embedded Wallet internal account this key may sign for. For a card key, Grid uses the (cardId, internalAccountId) pair to find the active card funding-source binding. For an agent key, the account must belong to the agent's customer.

Example:

"InternalAccount:019542f5-b3e7-1d02-0000-000000000002"

nickname
string
required

Human-readable label for the delegated key.

Required string length: 1 - 256
Example:

"Payments key"

cardId
string

The id of the card whose Embedded Wallet funding account will use this delegated signing key. Omit when creating a key for an agent.

Example:

"Card:019542f5-b3e7-1d02-0000-000000000010"

agentId
string

The id of the agent that will use this delegated signing key. The agent must belong to the customer that owns the Embedded Wallet internal account. Omit when creating a key for a card.

Example:

"Agent:019542f5-b3e7-1d02-0000-000000000042"

Response

Delegated key created and policy granted. The key is ACTIVE and Grid may use it to stamp card-payment quote executions or policy-approved actions for the selected agent.

A delegated signing key for either a card funding source or an agent, backed by an Embedded Wallet internal account. Card keys include cardId and fundingSourceId; agent keys include agentId. Returned from POST /auth/delegated-keys (on activation), GET /auth/delegated-keys (list), and GET /auth/delegated-keys/{id}. The keypair is generated and custodied by Grid; the private key is never returned. While ACTIVE, Grid may use the key to authorize Spark token-transaction signing for the selected card funding source or agent in place of a session keypair. publicKey is informational metadata identifying the credential.

id
string
required

Grid-issued DelegatedKey:<uuid> identifier.

Example:

"DelegatedKey:019542f5-b3e7-1d02-0000-000000000021"

accountId
string
required

The Embedded Wallet internal account this key is delegated for, derived from the card funding source or the agent's customer.

Example:

"InternalAccount:019542f5-b3e7-1d02-0000-000000000002"

publicKey
string
required

Compressed P-256 public key (hex) of the delegated API keypair.

Example:

"02a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90"

nickname
string
required

Human-readable label for the delegated key.

Example:

"Settlement service key"

status
enum<string>
required

Status of a delegated signing key.

  • PENDING: The delegated user exists but the policy-creation leg never completed. The key cannot sign.
  • ACTIVE: The policy is granted and the key may stamp quote executions.
  • REVOKED: The delegated user has been deleted and the key can no longer sign.
Available options:
PENDING,
ACTIVE,
REVOKED
Example:

"ACTIVE"

createdAt
string<date-time>
required

When the delegated key was created.

Example:

"2026-04-08T15:30:01Z"

updatedAt
string<date-time>
required

When the delegated key was last updated.

Example:

"2026-04-08T15:30:42Z"

cardId
string

The card this key is delegated for. Present only for card keys.

Example:

"Card:019542f5-b3e7-1d02-0000-000000000010"

fundingSourceId
string

The card funding source this key is delegated for. Present only for card keys.

Example:

"CardFundingSource:019542f5-b3e7-1d02-0000-000000000011"

agentId
string

The agent this key is delegated for. Present only for agent keys.

Example:

"Agent:019542f5-b3e7-1d02-0000-000000000042"