KPN

KPN Organization Keys API

Signing keys at organization scope. Applied to all webhook deliveries in your organization unless a team or application key overrides them. KPN auto-provisions an organization key on first delivery if none exists. In the next version scopes will be included for Organization level.

Operations 6

POST /organizations/keys Create organization signing key #
GET /organizations/keys List organization signing keys #
GET /organizations/keys/reveal Reveal active org signing key secret #
POST /organizations/keys/{key_id}/activate Activate a staged org signing key #
POST /organizations/keys/{key_id}/retire Retire a retiring org signing key #
DELETE /organizations/keys/{key_id} Delete a retired org signing key #

Documentation

📖
Documentation
https://developer.kpn.com/products/kpn-number-verify
📖
Documentation
https://developer.kpn.com/documentation/kpn-number-verify-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/numberverify-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-account-takeover-protection
📖
Documentation
https://developer.kpn.com/documentation/kpn-account-takeover-protection-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/simswap-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-match
📖
Documentation
https://developer.kpn.com/documentation/kpn-match-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/match-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-sms-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-sms-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/sms-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/sms-inbound
📖
Documentation
https://developer.kpn.com/products/kpn-mobile-services-management-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-mobile-services-management-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/mobileservicesmanagement-kpn
📖
Documentation
https://developer.kpn.com/products/federated-identity-and-access-management
📖
Documentation
https://developer.kpn.com/documentation/fiam-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/fiam-kpn
📖
Documentation
https://developer.kpn.com/products/fiam-eneco-data-products
📖
Documentation
https://developer.kpn.com/documentation/eneco-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/fiam-eneco-data-products
📖
Documentation
https://developer.kpn.com/products/kpn-disturbance-check-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-disturbance-check-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/disturbance-check-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-internet-speed-check-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-internet-speed-check-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/internet-speed-check-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-high-level-design-fttx-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-high-level-design-fttx-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/high-level_design_ftth
📖
Documentation
https://developer.kpn.com/products/kpn-lora-device-management-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-lora-device-management-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/lora-device-management-kpn
📖
Documentation
https://developer.kpn.com/products/kpn-sd-lan-sd-wan-network-view-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-sd-lan-sd-wan-network-view-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/kpn-sd_lan_sd_wan_network_view_api
📖
Documentation
https://developer.kpn.com/products/kpn-servicenow-connect-api
📖
Documentation
https://developer.kpn.com/documentation/kpn-servicenow-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/servicenow-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/ise-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/tv-guide-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/webhook-signing-key-management-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/webhook-privacy-config-manager
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/wholesale-wba-kpn
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/wholesale-broadband_access_fpi_cip
📖
Documentation
https://developer.kpn.com/products/pollyhelp-knowledge-management-api
📖
Documentation
https://developer.kpn.com/documentation/pollyhelp-knowledge-management-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/knowledge-management-polly.help
📖
Documentation
https://developer.kpn.com/products/xdroid-speech-text-api
📖
Documentation
https://developer.kpn.com/documentation/xdroid-xdroid-speech-text-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/speech-to-text-xdroid
📖
Documentation
https://developer.kpn.com/products/parley-secure-messenger-api
📖
Documentation
https://developer.kpn.com/documentation/parley-chat-and-messaging-api-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/secure-messenger-parley
📖
Documentation
https://developer.kpn.com/products/social-media-chat-and-messaging
📖
Documentation
https://developer.kpn.com/documentation/parley-webcare-parley-documentation-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/socialmediawebcare-tracebuzz
📖
Documentation
https://developer.kpn.com/products/weseedo-weseedo-direct-api
📖
Documentation
https://developer.kpn.com/documentation/weseedo-weseedo-direct-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/weseedo-direct-weseedo
📖
Documentation
https://developer.kpn.com/products/weseedo-weseedo-personal-api
📖
Documentation
https://developer.kpn.com/documentation/weseedo-weseedo-personal-weseedo-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/weseedo-personal-weseedo
📖
Documentation
https://developer.kpn.com/products/vonage-messages-api
📖
Documentation
https://developer.kpn.com/documentation/vonage-messages-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/messages-nexmo
📖
Documentation
https://developer.kpn.com/products/vonage-voice-api
📖
Documentation
https://developer.kpn.com/documentation/vonage-voice-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/voice-nexmo
📖
Documentation
https://developer.kpn.com/products/vonage-phone-numbers-api
📖
Documentation
https://developer.kpn.com/documentation/vonage-phone-numbers-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/phone-numbers-nexmo
📖
Documentation
https://developer.kpn.com/products/vonage-number-insight-api
📖
Documentation
https://developer.kpn.com/documentation/vonage-number-insight-api-documentation
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/number-insight-nexmo
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/sms-nexmo
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/verify-nexmo
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/apidaze-voice-voip-innovations
📖
APIReference
https://app.swaggerhub.com/apis-docs/kpn/registeredemail-registeredemail

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/kpn-organization-keys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

kpn-organization-keys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Webhook Signing Keys - KPN Organization Keys API
  description: 'When KPN delivers a webhook to your endpoint, signing keys are to know the request genuinely

    came from KPN and wasn''t tampered with in transit.'
  version: 4.0.0
  contact:
    name: API Support
    email: api_developer@kpn.com
    url: https://developer.kpn.com/support
  termsOfService: https://developer.kpn.com/legal
servers:
- description: SwaggerHub API Auto Mocking
  url: https://virtserver.swaggerhub.com/kpn/webhook-signing-key-management-kpn/4.0.0
- url: https://api-prd.kpn.com/webhookconfigs-kpn
  description: Production
security:
- OAuth2: []
tags:
- name: Organization Keys
  description: 'Signing keys at organization scope. Applied to all webhook deliveries in your

    organization unless a team or application key overrides them. KPN auto-provisions

    an organization key on first delivery if none exists. In the next version scopes will be included for Organization level.'
paths:
  /organizations/keys:
    post:
      operationId: createOrgSigningKey
      tags:
      - Organization Keys
      summary: Create organization signing key
      description: 'Creates a new signing key at organization scope.


        - `staged: false` (default) — key becomes **active** immediately; any previously

        active org key is moved to **retiring** automatically.

        - `staged: true` — key is created as **staged**; activate it later via

        `POST /organizations/keys/{key_id}/activate`.'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SigningKeyCreateRequest'
            examples:
              activeKey:
                summary: Create and immediately activate
                value:
                  secret: my-shared-secret-at-least-32-chars-long
              stagedKey:
                summary: Create in staged state (activate later)
                value:
                  secret: my-shared-secret-at-least-32-chars-long
                  staged: true
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
    get:
      operationId: listOrgSigningKeys
      tags:
      - Organization Keys
      summary: List organization signing keys
      description: Lists all signing keys at organization scope. Secrets are never included — use `/reveal` for the active key's plaintext.
      parameters:
      - $ref: '#/components/parameters/StatusFilter'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/SigningKeyResponse'
              example:
              - key_id: wk_2C6EDCDFDFD944F3A75D0D36
                status: active
                created_at: '2026-06-10T11:56:04.136Z'
                updated_at: '2026-06-10T11:56:04.361Z'
              - key_id: wk_1A3BCDEFFE2311E0B94E0A25
                status: retiring
                created_at: '2026-05-01T08:00:00.000Z'
                updated_at: '2026-06-10T11:56:04.361Z'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
  /organizations/keys/reveal:
    get:
      operationId: revealOrgSigningKeySecret
      tags:
      - Organization Keys
      summary: Reveal active org signing key secret
      description: 'Returns the **decrypted plaintext secret** for the currently active

        organization signing key.


        Use this to configure your webhook receiver for HMAC-SHA256 signature

        verification. Treat this value like a password — never log or expose it.'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyRevealResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          description: No active signing key found for your organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '500':
          $ref: '#/components/responses/InternalServerError'
  /organizations/keys/{key_id}/activate:
    post:
      operationId: activateOrgSigningKey
      tags:
      - Organization Keys
      summary: Activate a staged org signing key
      description: 'Transitions the key from `staged` to `active`.

        Any currently `active` org key is automatically moved to `retiring`.


        Only keys in `staged` state can be activated.'
      parameters:
      - $ref: '#/components/parameters/KeyId'
      responses:
        '200':
          description: Activated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyResponse'
        '400':
          description: Key is not in staged state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
  /organizations/keys/{key_id}/retire:
    post:
      operationId: retireOrgSigningKey
      tags:
      - Organization Keys
      summary: Retire a retiring org signing key
      description: 'Transitions the key from `retiring` to `retired`.


        Wait until all in-flight webhook deliveries signed with this key have been

        verified before retiring it. Retiring keys can still be used for verification

        but will not sign new deliveries.


        Only keys in `retiring` state can be retired.'
      parameters:
      - $ref: '#/components/parameters/KeyId'
      responses:
        '200':
          description: Retired
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyResponse'
        '400':
          description: Key is not in retiring state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
  /organizations/keys/{key_id}:
    delete:
      operationId: deleteOrgSigningKey
      tags:
      - Organization Keys
      summary: Delete a retired org signing key
      description: 'Permanently deletes the signing key record.

        Only keys in `retired` state can be deleted.'
      parameters:
      - $ref: '#/components/parameters/KeyId'
      responses:
        '204':
          description: Deleted
        '400':
          description: Key is not in retired state.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiErrorResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  responses:
    NotFound:
      description: Not found — the requested key does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorResponse'
          example:
            errorResponse:
              code: '404'
              message: Not Found
              info: https://developer.kpn.com/documentation-webhook-signing-keys
    Unauthorized:
      description: Unauthorized — missing or invalid Bearer token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorResponse'
          example:
            errorResponse:
              code: '401'
              message: Unauthorized
              info: https://developer.kpn.com/getting-started
    Forbidden:
      description: Forbidden — your token does not have permission to access this resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorResponse'
          example:
            errorResponse:
              code: '403'
              message: Forbidden
              info: https://developer.kpn.com/support
    BadRequest:
      description: Bad request — check your request body for missing or invalid fields.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorResponse'
          example:
            errorResponse:
              code: '400'
              message: Bad Request
              info: https://developer.kpn.com/documentation-webhook-signing-keys
    InternalServerError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorResponse'
          example:
            errorResponse:
              code: '500'
              message: Internal Server Error
              info: https://developer.kpn.com/support
  parameters:
    KeyId:
      in: path
      name: key_id
      required: true
      schema:
        type: string
      description: The `key_id` returned by the create or list endpoint.
      example: wk_2C6EDCDFDFD944F3A75D0D36
    StatusFilter:
      in: query
      name: status
      required: false
      description: Filter keys by lifecycle status.
      schema:
        type: string
        enum:
        - STAGED
        - ACTIVE
        - RETIRING
        - RETIRED
  schemas:
    SigningKeyCreateRequest:
      type: object
      required:
      - secret
      properties:
        key_id:
          type: string
          maxLength: 128
          description: 'Optional custom identifier for this key. If omitted, a `wk_`-prefixed ID is

            generated automatically (e.g. `wk_2C6EDCDFDFD944F3A75D0D36`).

            '
        secret:
          type: string
          minLength: 1
          maxLength: 4096
          description: 'The shared secret used for HMAC-SHA256 signing of outbound webhook payloads.

            Configure your webhook receiver with this value to verify incoming signatures.

            **This value is never returned after creation** — use the `/reveal` endpoint

            to retrieve it for the currently active key.

            '
        staged:
          type: boolean
          default: false
          description: '`false` (default) — key becomes active immediately; any previously active key

            at the same scope is moved to retiring automatically.


            `true` — key is created in staged state. Use this for zero-downtime rotation:

            update your receiver first, then activate the key.

            '
    SigningKeyRevealResponse:
      type: object
      description: 'Contains the decrypted plaintext secret for the active signing key.

        **Treat this like a password** — do not log or expose it.

        '
      properties:
        key_id:
          type: string
          example: wk_2C6EDCDFDFD944F3A75D0D36
        secret:
          type: string
          description: Plaintext HMAC-SHA256 shared secret. Configure your receiver with this value.
        status:
          type: string
          enum:
          - active
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    SigningKeyResponse:
      type: object
      description: Signing key metadata. Does not include the secret value.
      properties:
        key_id:
          type: string
          example: wk_2C6EDCDFDFD944F3A75D0D36
        status:
          type: string
          enum:
          - staged
          - active
          - retiring
          - retired
          description: Current lifecycle state of the key.
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ApiErrorResponse:
      type: object
      properties:
        errorResponse:
          type: object
          properties:
            code:
              type: string
              description: HTTP status code as a string.
              example: '400'
            message:
              type: string
              description: Human-readable error message.
            info:
              type: string
              description: URL to relevant documentation or support page.
  securitySchemes:
    OAuth2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://api-prd.kpn.com/oauth/client_credential/accesstoken?grant_type=client_credentials
          scopes: {}