Verifies a detached-JWS (oldJws) under oldKid—
either the header's kid or sourceKidOverride
if the header lacks a kid—and immediately signs the same payload with
newKid. The response is multipart/mixed (PRD §64):
PART 1 (application/octet-stream) is the new detached-JWS JSON and the
trailing PART 2 (application/json) is a StreamVerdict emitted
AFTER the source (old) signature is verified — an INVALID verdict signals a
source-signature failure discovered at end-of-stream.
Supports all key type combinations:
• SIMPLE → SIMPLE (single signature → single signature)
• SIMPLE → COMPOSITE (single signature → multiple signatures)
• COMPOSITE → COMPOSITE (multiple signatures → multiple signatures)
• COMPOSITE → SIMPLE (multiple signatures → single signature)
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||