Create a delegated signing key
Delegate Spark token-transaction signing authority for a card funding source or agent backed by an Embedded Wallet internal account to a Grid-custodied P-256 API key. Grid uses the requested owner and internal account to identify the wallet, generates the keypair server-side, creates an isolated signer identity holding the public key, then policies granting that identity signing and self-revocation authority. The private key is custodied by Grid and never returned. Both activities must be authorized by the wallet owner, so creation is a three-leg signed-retry flow:
-
Call
POST /auth/delegated-keyswith no signature headers. Grid generates the delegated keypair and the response is202with apayloadToSign,requestId, andexpiresAt. -
Use the session API keypair of a verified credential on the requested Embedded Wallet internal account to build an API-key stamp over
payloadToSign, then retry the same request with that full stamp as theGrid-Wallet-Signatureheader and therequestIdechoed back as theRequest-Idheader. The response is a second202with a newpayloadToSign,requestId, andexpiresAt. -
Stamp the new
payloadToSignwith the same session keypair and retry once more with the newRequest-Id. The signed retry returns201with the createdDelegatedKeyinACTIVEstatus. For card keys, a provisionedPENDING_AUTHcard using this funding source becomesACTIVEautomatically. Cards still provisioning remainPROCESSING; frozen and closed cards retain their status.
The same request body must be sent on all three legs. A flow abandoned after the second leg leaves the key in PENDING status: the signer identity exists but holds no policies, so it cannot sign or revoke itself. Abandoned PENDING keys do not block creating another delegated key. After activation, Grid uses the custodied key to authorize signing for the card’s Embedded Wallet funding account or for policy-approved agent actions in place of a session keypair; the platform never handles the key material.
Each card funding source, or each agent and Embedded Wallet pair, may have at most one ACTIVE delegated key; revoke the existing active key before creating a new one. A delegated key authorizes raw-payload signing for the wallet and cannot be scoped to amounts or recipients by the public API. Revoke it with DELETE /auth/delegated-keys/{id} when no longer needed.
Authorizations
API token authentication using format <api token id>:<api client secret>
Headers
Full API-key stamp built over the prior payloadToSign with the session API keypair of a verified credential on the same internal account. Required on the signed retries; ignored on the initial call.
The requestId returned in the prior 202 response, echoed back exactly on the signed retry so the server can correlate it with the issued challenge. Required on the signed retries; must be paired with Grid-Wallet-Signature.
Body
Creates a delegated signing key for a card funding source or an agent. Exactly one of cardId or agentId is required. Requests that provide both fields or neither field return a 400 response.
The id of the Embedded Wallet internal account this key may sign for. For a card key, Grid uses the (cardId, internalAccountId) pair to find the active card funding-source binding. For an agent key, the account must belong to the agent's customer.
"InternalAccount:019542f5-b3e7-1d02-0000-000000000002"
Human-readable label for the delegated key.
1 - 256"Payments key"
The id of the card whose Embedded Wallet funding account will use this delegated signing key. Omit when creating a key for an agent.
"Card:019542f5-b3e7-1d02-0000-000000000010"
The id of the agent that will use this delegated signing key. The agent must belong to the customer that owns the Embedded Wallet internal account. Omit when creating a key for a card.
"Agent:019542f5-b3e7-1d02-0000-000000000042"
Response
Delegated key created and policy granted. The key is ACTIVE and Grid may use it to stamp card-payment quote executions or policy-approved actions for the selected agent.
A delegated signing key for either a card funding source or an agent, backed by an Embedded Wallet internal account. Card keys include cardId and fundingSourceId; agent keys include agentId. Returned from POST /auth/delegated-keys (on activation), GET /auth/delegated-keys (list), and GET /auth/delegated-keys/{id}. The keypair is generated and custodied by Grid; the private key is never returned. While ACTIVE, Grid may use the key to authorize Spark token-transaction signing for the selected card funding source or agent in place of a session keypair. publicKey is informational metadata identifying the credential.
Grid-issued DelegatedKey:<uuid> identifier.
"DelegatedKey:019542f5-b3e7-1d02-0000-000000000021"
The Embedded Wallet internal account this key is delegated for, derived from the card funding source or the agent's customer.
"InternalAccount:019542f5-b3e7-1d02-0000-000000000002"
Compressed P-256 public key (hex) of the delegated API keypair.
"02a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4e5f60718293a4b5c6d7e8f90"
Human-readable label for the delegated key.
"Settlement service key"
Status of a delegated signing key.
PENDING: The delegated user exists but the policy-creation leg never completed. The key cannot sign.ACTIVE: The policy is granted and the key may stamp quote executions.REVOKED: The delegated user has been deleted and the key can no longer sign.
PENDING, ACTIVE, REVOKED "ACTIVE"
When the delegated key was created.
"2026-04-08T15:30:01Z"
When the delegated key was last updated.
"2026-04-08T15:30:42Z"
The card this key is delegated for. Present only for card keys.
"Card:019542f5-b3e7-1d02-0000-000000000010"
The card funding source this key is delegated for. Present only for card keys.
"CardFundingSource:019542f5-b3e7-1d02-0000-000000000011"
The agent this key is delegated for. Present only for agent keys.
"Agent:019542f5-b3e7-1d02-0000-000000000042"