How Agent API signing uses keys
The Agent API performs supported cryptographic operations with key material stored encrypted by the Neuron. Your application retains the key identifier, algorithm metadata, and the credentials required to authorize its use. Keep key passwords distinct from account passwords. A request must bind the acting account, selected key, intended payload, and signing purpose. The Agent API is the same HTTPS interface for ordinary and AI-enabled applications.Key workflow
Application rules
- Keep passwords, JWTs, key passwords, private keys, and signing secrets out of source control and logs.
- Persist the
idsubmitted toCreateKey; later operations call the same valuekeyId. - Make the actor, key, payload, and intended signing purpose explicit.
- Do not claim legal effect or non-repudiation solely because bytes have a valid cryptographic signature; the identity, authorization, contract, policy, and verification context also matter.
- Treat retries carefully. A signing operation may have effects that should not be duplicated unless idempotency is explicitly documented.