identitykeysapp.example.com

app.example.com

tls-cert·7-of-21·ECDSA-secp256r1 (CGGMP24)·key:kms:tls:app.example.com
Capability tokens · 4 active
Each capability authorizes a specific service to request signatures with this key. Time-boxed, rate-limited, revocable.
BEARERSCOPEISSUED BYEXPIRESRATE LIMITUSED · 24h
edge-pool-us-westthreshold-sign · app.example.comdid:grid:pub:mk2…r460d (rolling)1k/hr30268
edge-pool-euthreshold-sign · app.example.comdid:grid:pub:mk2…r460d (rolling)1k/hr15134
edge-pool-apacthreshold-sign · app.example.comdid:grid:pub:mk2…r460d (rolling)500/hr3417
acme-bridgerenew-cert · app.example.comdid:grid:pub:mk2…r41d (one-shot)1/d0
Rate limit policy
Per-cap rate cap

Maximum sigs/hr a single capability can request, regardless of what you grant it.

Burst allowance

Extra sigs allowed in a 60s burst above the rate.

Auto-throttle on anomaly

If signature rate exceeds historical p99, automatically reduce to p95 and notify.

Revoked capabilities · last 30 days
BEARERSCOPEREVOKEDREASON
old-edge-pool-iadthreshold-sign8d agopool decommissioned
staging-edgethreshold-sign22d agoexpired naturally