openapi: 3.0.1 info: title: Turnkey Organizations Users & Policies API description: 'Turnkey is secure wallet infrastructure: an API-first key-management and signing platform that generates private keys and signs payloads inside verifiable secure enclaves (TEEs). The public API is an RPC-style REST API under https://api.turnkey.com/public/v1 split into two families - read-only `query` endpoints and state-changing `submit` activity endpoints. Every request is an HTTP POST carrying an `X-Stamp` (or `X-Stamp-Webauthn`) header containing a digital signature over the exact JSON POST body. The stamp is verified by Turnkey''s secure enclaves before the request is processed and checked against the organization''s policy engine.' termsOfService: https://www.turnkey.com/legal/terms contact: name: Turnkey Support url: https://docs.turnkey.com version: '1.0' servers: - url: https://api.turnkey.com security: - apiStamp: [] tags: - name: Users & Policies description: Users, authenticators, API keys, and the policy engine. paths: /public/v1/submit/create_policies: post: operationId: createPolicies tags: - Users & Policies summary: Create policies description: Adds one or more policies to the policy engine that authorizes activities. Activity type ACTIVITY_TYPE_CREATE_POLICIES. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SubmitActivityEnvelope' responses: '200': description: Activity accepted/completed. content: application/json: schema: $ref: '#/components/schemas/ActivityResponse' /public/v1/submit/create_users: post: operationId: createUsers tags: - Users & Policies summary: Create users description: Adds users to an organization with associated API keys and authenticators. Activity type ACTIVITY_TYPE_CREATE_USERS_V3. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SubmitActivityEnvelope' responses: '200': description: Activity accepted/completed. content: application/json: schema: $ref: '#/components/schemas/ActivityResponse' /public/v1/submit/create_authenticators: post: operationId: createAuthenticators tags: - Users & Policies summary: Create authenticators description: Registers WebAuthn/passkey authenticators for a user. Activity type ACTIVITY_TYPE_CREATE_AUTHENTICATORS_V2. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SubmitActivityEnvelope' responses: '200': description: Activity accepted/completed. content: application/json: schema: $ref: '#/components/schemas/ActivityResponse' /public/v1/query/list_users: post: operationId: listUsers tags: - Users & Policies summary: List users description: Lists users in an organization. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OrganizationScopedQuery' responses: '200': description: List of users. content: application/json: schema: type: object /public/v1/query/list_policies: post: operationId: listPolicies tags: - Users & Policies summary: List policies description: Lists policies in an organization. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OrganizationScopedQuery' responses: '200': description: List of policies. content: application/json: schema: type: object /public/v1/query/whoami: post: operationId: whoami tags: - Users & Policies summary: Who am I description: Returns the organization and user associated with the stamping credential of the request. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WhoamiRequest' responses: '200': description: Caller identity. content: application/json: schema: $ref: '#/components/schemas/WhoamiResponse' components: schemas: WhoamiResponse: type: object properties: organizationId: type: string organizationName: type: string userId: type: string username: type: string ActivityResponse: type: object description: Standard activity envelope returned by submit and query endpoints. properties: activity: type: object properties: id: type: string organizationId: type: string status: type: string enum: - ACTIVITY_STATUS_CREATED - ACTIVITY_STATUS_PENDING - ACTIVITY_STATUS_COMPLETED - ACTIVITY_STATUS_FAILED - ACTIVITY_STATUS_CONSENSUS_NEEDED - ACTIVITY_STATUS_REJECTED type: type: string result: type: object description: Activity-specific result, e.g. createWalletResult {walletId, addresses[]} or signTransactionResult {signedTransaction} or signRawPayloadResult {r, s, v}. WhoamiRequest: type: object required: - organizationId properties: organizationId: type: string OrganizationScopedQuery: type: object required: - organizationId properties: organizationId: type: string SubmitActivityEnvelope: type: object description: Common envelope for all submit (mutation) activities. The `type` selects the activity and `parameters` carries the activity-specific body. required: - type - timestampMs - organizationId - parameters properties: type: type: string description: The ACTIVITY_TYPE_* discriminator for this activity. example: ACTIVITY_TYPE_CREATE_WALLET timestampMs: type: string description: Client timestamp in milliseconds, replay-protected. example: '1746736509954' organizationId: type: string description: The organization or sub-organization id the activity targets. parameters: type: object description: Activity-specific parameters. securitySchemes: apiStamp: type: apiKey in: header name: X-Stamp description: Base64URL-encoded JSON stamp `{publicKey, signature, scheme}` where `signature` is a DER-encoded, hex-encoded signature over the exact JSON POST body produced by the registered API key. `scheme` is one of SIGNATURE_SCHEME_TK_API_P256, SIGNATURE_SCHEME_TK_API_SECP256K1, SIGNATURE_SCHEME_TK_API_ED25519, or SIGNATURE_SCHEME_TK_API_SECP256K1_EIP191. Passkey-stamped requests use the alternate `X-Stamp-Webauthn` header carrying a WebAuthn assertion `{credentialId, authenticatorData, clientDataJson, signature}` (plain JSON, not base64URL-encoded) over a SHA256 hash of the POST body. webauthnStamp: type: apiKey in: header name: X-Stamp-Webauthn description: Plain-JSON WebAuthn assertion stamp for passkey-authenticated requests.