rotate_credential
Replace the subject's active signing credential. Authorized by the current signing credential; the new key proves possession by signing the term-rotation-v1 statement with its private key (never sent here). Activation is immediate cutover: the retired key authorizes nothing the instant the rotation commits, and a replaced key can never become current again.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| proof | Yes | Ed25519 signature over the term-rotation-v1 statement, signed by the new credential's private key. | |
| proof_created | Yes | Unix seconds when the proof statement was signed; within ±300 s of server time. | |
| new_signing_public_key | Yes | Ed25519 raw 32-byte public key, unpadded base64url. Never provide a private key. |