---
title: "Get a specific public signing key."
method: GET
path: "/api/signing-key/{keyId}"
tags: ["Signing"]
---

# Get a specific public signing key.

`GET /api/signing-key/{keyId}`

Returns a retained public signing key by its id, in PEM form. A key that has been superseded by a regeneration is kept, because redaction-ledger entries signed with it must remain verifiable. Ledger entries and exports name the key that signed them in their signingKeyId field. This endpoint does not require authentication.

## Path parameters

- `keyId` string, required

## Response `200`

The public key with the given id.

- string

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `404` — No key with that id is retained.
- `413` — Content Too Large
- `415` — Unsupported Media Type
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-08-04** `ee79a60eea42` — 1 info
  - added the non-success response with the status `415`
- **2026-08-04** `755bc1bbdc38` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/philterd/apis/philter-api/changes/api/signing-key/:keyId/get.md)

---

[API](https://skmtc.dev/philterd/apis/philter-api.md) · [All operations](https://skmtc.dev/philterd/apis/philter-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/philterd/philter-api/revisions/d90a12a66fa6/schema)
