> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nerves-hub.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a new Signing Key for an Organization

> The `scheme` decides how `key` is validated and what it can verify:

  * `ed25519` (the default) — an fwup signing key, base64 encoded, as
    produced by `fwup -g`. Verifies `.fw` archives.
  * `secure_boot_v2_rsa` — a PEM-encoded RSA-3072 public key, the public
    half of an `espsecure.py` Secure Boot v2 signing key. Verifies ESP-IDF
    `.bin` images.

A key is only ever a candidate for firmware of its own scheme.




## OpenAPI

````yaml https://manage.nervescloud.com/api/openapi post /api/orgs/{org_name}/keys
openapi: 3.0.0
info:
  description: >
    The NervesCloud API gives users full access to their

    Orgs, Products, and corresponding Device fleets.


    The API can be used to integrate with your own systems, providing full
    access to your Product and Device data.


    The API is documented using the OpenAPI 3.0 specification.
  title: NervesCloud API
  version: 2.0.0
servers:
  - url: https://manage.nervescloud.com
    variables: {}
security:
  - bearer_auth: []
tags:
  - description: User authentication and API token creation
    name: Auth
  - description: Organization Certificate Authority management
    name: CA Certificates
  - description: >-
      Device management, including action requests eg. upgrade, reboot,
      reconnect
    name: Devices
  - description: Log lines Devices have sent over the logging extension
    name: Device Logs
  - description: >-
      Device management, including action requests eg. upgrade, reboot,
      reconnect
    name: Devices (short URL)
  - description: Device Certificate management
    name: Device Certificates
  - description: Identities a Device holds on networks NervesHub does not run
    name: Network Identities
  - description: Deployment Group and release management
    name: Deployment Groups
  - description: Firmware uploading and management
    name: Firmwares
  - description: Organization iroh endpoint id registration
    name: Iroh Endpoints
  - description: Organization management
    name: Organizations
  - description: Organization User membership management
    name: Organization Members
  - description: Product management
    name: Products
  - description: Organization Signing Key management
    name: Signing Keys
  - description: Product Support Script management
    name: Support Scripts
  - description: Platform healthcheck
    name: Platform Status
paths:
  /api/orgs/{org_name}/keys:
    post:
      tags:
        - Signing Keys
      summary: Create a new Signing Key for an Organization
      description: |
        The `scheme` decides how `key` is validated and what it can verify:

          * `ed25519` (the default) — an fwup signing key, base64 encoded, as
            produced by `fwup -g`. Verifies `.fw` archives.
          * `secure_boot_v2_rsa` — a PEM-encoded RSA-3072 public key, the public
            half of an `espsecure.py` Secure Boot v2 signing key. Verifies ESP-IDF
            `.bin` images.

        A key is only ever a candidate for firmware of its own scheme.
      operationId: NervesHubWeb.API.KeyController.create
      parameters:
        - description: Organization Name
          example: example_org
          in: path
          name: org_name
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SigningKeyCreationRequest'
        description: Signing Key creation request body
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyShowResponse'
          description: Signing Key
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Forbidden
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChangesetErrorResponse'
          description: Unprocessable Entity
      callbacks: {}
      security:
        - bearer_auth: []
components:
  schemas:
    SigningKeyCreationRequest:
      description: |
        POST body for adding a Signing Key to an Organization.

        `scheme` defaults to `ed25519` when omitted, which is what every key was
        before ESP-IDF support — so existing clients keep working unchanged.
      example:
        key: |
          -----BEGIN PUBLIC KEY-----
          MIIBoj...
          -----END PUBLIC KEY-----
        name: ESP release
        scheme: secure_boot_v2_rsa
      properties:
        key:
          type: string
        name:
          type: string
        scheme:
          description: Signature scheme this key belongs to
          enum:
            - ed25519
            - secure_boot_v2_rsa
          type: string
      required:
        - name
        - key
      title: SigningKeyCreationRequest
      type: object
    SigningKeyShowResponse:
      description: Response schema for a single Signing Key
      example:
        data:
          key: abc123=
          name: QA
          scheme: ed25519
      properties:
        data:
          $ref: '#/components/schemas/SigningKey'
      title: SigningKeyShowResponse
      type: object
    ErrorResponse:
      description: Error response
      example:
        errors:
          detail: Resource Not Found or Authorization Insufficient
      properties:
        errors:
          properties:
            detail:
              type: string
          type: object
      title: ErrorResponse
      type: object
    ChangesetErrorResponse:
      description: Validation error response
      example:
        errors:
          identifier:
            - can't be blank
      properties:
        errors:
          additionalProperties:
            items:
              type: string
            type: array
          type: object
      title: ChangesetErrorResponse
      type: object
    SigningKey:
      example:
        key: abc123=
        name: CI
        scheme: ed25519
      properties:
        key:
          type: string
        name:
          type: string
        scheme:
          description: Signature scheme this key belongs to
          enum:
            - ed25519
            - secure_boot_v2_rsa
          type: string
      title: SigningKey
      type: object
  securitySchemes:
    bearer_auth:
      scheme: bearer
      type: http

````