> ## Documentation Index
> Fetch the complete documentation index at: https://docs.niadra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Contact token public keys

> The Ed25519 keys of one space, as JWKs, with which your gateway checks a contact token without talking to Niadra. Public.



## OpenAPI

````yaml openapi/en/cell.json GET /.well-known/niadra-contact-keys.json
openapi: 3.1.0
info:
  title: Niadra data API
  version: '1'
  description: >-
    Writing, context, history, objects, identity, privacy and governance of one
    space. Every space has a stable address, with the space and the region in
    its name.
servers:
  - url: https://{space}.{region}.api.niadra.com
    variables:
      space:
        default: acme-prod
        description: The space, which comes in the source key.
      region:
        default: us-east-2
        description: The region of the space, which also comes in the key.
security: []
paths:
  /.well-known/niadra-contact-keys.json:
    get:
      tags:
        - coordination
      summary: Contact token public keys
      description: >-
        The public keys a gateway checks a contact token with, offline: a JWK
        set (RFC 8037, `OKP` and `Ed25519`) of one space, named by `space`. A
        key is `active` or `retiring`: a retiring key signs nothing new and
        still verifies what it signed until `not_after`. Cache it, refresh it at
        least hourly, and on an unknown `kid` refresh at most once a minute
        before refusing.


        **Authentication.** No authentication.
      operationId: contact_keys__well_known_niadra_contact_keys_json_get
      parameters:
        - in: query
          name: space
          required: true
          schema:
            format: uuid
            title: Space
            type: string
          description: The space whose keys to list. No caller may list a cell's spaces.
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContactKeys'
          description: The key set of the space.
        '404':
          description: No such space, or it has no coordination.
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
          description: The request does not match the contract.
      security: []
      x-codeSamples:
        - lang: python
          label: Python
          source: >-
            # At your gateway: check the token offline, with the space's public
            keys kept in memory

            gateway = niadra.contact_gateway("wa_gateway", space=SPACE_ID,
            key=GATEWAY_KEY)

            claims = gateway.verify(token, channel="whatsapp",
            destination="phone:+5511987654321")  # raises ContactTokenError
        - lang: typescript
          label: TypeScript
          source: >-
            // At your gateway: check the token offline, with the space's public
            keys kept in memory

            const gateway = niadra.contactGateway("wa_gateway", { space:
            SPACE_ID, key: GATEWAY_KEY });

            const claims = await gateway.verify(token, { channel: "whatsapp",
            destination: "phone:+5511987654321" }); // rejects with
            NiadraContactTokenError
components:
  schemas:
    ContactKeys:
      additionalProperties: false
      description: A space's public keys a gateway checks a contact token with, offline.
      properties:
        keys:
          items:
            $ref: '#/components/schemas/ContactKey'
          title: Keys
          type: array
      required:
        - keys
      title: ContactKeys
      type: object
    Problem:
      additionalProperties: false
      description: RFC 9457 problem details; `code` comes from the versioned error catalog.
      properties:
        code:
          title: Code
          type: string
        detail:
          anyOf:
            - type: string
            - type: 'null'
          default: null
          title: Detail
        request_id:
          anyOf:
            - type: string
            - type: 'null'
          default: null
          title: Request Id
        status:
          title: Status
          type: integer
        title:
          title: Title
          type: string
        type:
          default: about:blank
          title: Type
          type: string
      required:
        - title
        - status
        - code
      title: Problem
      type: object
    ContactKey:
      additionalProperties: false
      description: >-
        An Ed25519 public key as a JWK (RFC 8037). A `retiring` key still
        verifies and signs nothing new.
      properties:
        crv:
          const: Ed25519
          default: Ed25519
          title: Crv
          type: string
        kid:
          pattern: ^[A-Za-z0-9_-]{8,64}$
          title: Kid
          type: string
        kty:
          const: OKP
          default: OKP
          title: Kty
          type: string
        not_after:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
          title: Not After
        space:
          format: uuid
          title: Space
          type: string
        status:
          default: active
          enum:
            - active
            - retiring
          title: Status
          type: string
        x:
          pattern: ^[A-Za-z0-9_-]{43}$
          title: X
          type: string
      required:
        - kid
        - x
        - space
      title: ContactKey
      type: object

````