openapi: 3.1.0 info: title: SSH Key Management Authorized Keys API description: A REST API for managing SSH keys, certificates, and access policies in infrastructure environments. Provides endpoints for key generation, certificate signing, authorized keys management, and host key verification. This represents common SSH management capabilities available via OpenSSH tooling and SSH certificate authority implementations. version: '1.0' contact: name: OpenSSH Project url: https://www.openssh.com/ license: name: BSD License url: https://www.openssh.com/portable.html servers: - url: https://api.openssh.example.com/v1 description: SSH Management API security: - BearerAuth: [] tags: - name: Authorized Keys description: Authorized keys management for users paths: /authorized-keys/{username}: get: operationId: getAuthorizedKeys summary: Get Authorized Keys description: Returns the authorized keys configured for a specific user. tags: - Authorized Keys parameters: - name: username in: path required: true schema: type: string responses: '200': description: Authorized keys content: application/json: schema: $ref: '#/components/schemas/AuthorizedKeysResponse' post: operationId: addAuthorizedKey summary: Add Authorized Key description: Adds a public key to a user's authorized_keys. tags: - Authorized Keys parameters: - name: username in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AuthorizedKeyCreate' responses: '201': description: Authorized key added content: application/json: schema: $ref: '#/components/schemas/AuthorizedKey' /authorized-keys/{username}/{keyId}: delete: operationId: removeAuthorizedKey summary: Remove Authorized Key description: Removes a key from a user's authorized_keys. tags: - Authorized Keys parameters: - name: username in: path required: true schema: type: string - name: keyId in: path required: true schema: type: string responses: '204': description: Key removed components: schemas: AuthorizedKeyCreate: type: object required: - publicKey properties: publicKey: type: string comment: type: string options: type: string AuthorizedKey: type: object properties: id: type: string publicKey: type: string comment: type: string options: type: string description: authorized_keys options string addedAt: type: string format: date-time AuthorizedKeysResponse: type: object properties: username: type: string keys: type: array items: $ref: '#/components/schemas/AuthorizedKey' securitySchemes: BearerAuth: type: http scheme: bearer bearerFormat: JWT