Ledger objects

Keys

Cryptographic keys control all transactions in an Onyx Mesh ledger. When creating an asset or account, you can specify one or more keys that must sign transactions before submitting to the ledger. To issue tokens of an asset, the transaction must be signed with the correct asset key(s). To transfer or retire tokens from an account, the transaction must be signed with the correct account key(s).

On this page

Keys are where a ledger is permissioned in the strongest sense. An API credential decides who may call the API; a key decides who may move a particular kind of token out of a particular account. The two are separate on purpose, so that read-write access to a ledger is not the same thing as authority over what is in it.

The simplest configuration is to use a single key to create all accounts and assets. This allows one system to control the entire ledger. However, if you have different systems responsible for different operations, you may want to create more than one key. For example, the system that issues tokens into accounts in response to external deposits may be different from the system that transfers tokens between accounts. In this case, you may want to create all the assets from one key (controlled by the first system) and all the accounts from another key (controlled by the second system).

Data StructureLink to this section

Field DescriptionsLink to this section

FieldTypeDescription
idstringUser-supplied or system-generated unique identifier of the key.

Example ObjectLink to this section

{
  id: "...",
}

ExamplesLink to this section

Create a keyLink to this section

Key key = new Key.Builder()
  .setId("myKey")
  .create(ledger);
ledger.keys.create({id: 'myKey'}).then(key => ...)
key = ledger.keys.create(id: 'my_key')

Query KeysLink to this section

You can retrieve keys that are managed by the ledger using a query. Results are sorted in descending order of creation time.

Key.ItemIterable keys = new Key.ListBuilder().getIterable(ledger);
for (Key key : keys) {
  System.out.println("key: " + key.id);
}
let all = ledger.keys.list().all()

while (true) {
  let { value: key, done: done } = await all.next()
  if (done) { break }
  console.log(key)
}
ledger.keys.list.each do |key|
  puts key.to_json
end