# Generate a public key

Generates a public key used to create a JWE token for passing secure authentication data through non-PCI compliant intermediaries.

## POST

/end-to-end-keys

## Ask

```shell
curl -X POST "https://api.moov.io/end-to-end-keys" \
  -H "Authorization: Bearer {token}" \
  -H "X-Moov-Version: v2026.04.00"
```

## Ask

```typescript
import { Moov } from "@moovio/sdk";

const moov = new Moov({
  security: {
    username: "",
    password: "",
  },
});

async function run() {
  const result = await moov.endToEndEncryption.generateKey();

console.log(result);
}

run();
```

## Ask

```php
declare(strict_types=1);

require 'vendor/autoload.php';

use Moov\MoovPhp;
use Moov\MoovPhp\Models\Components;

$sdk = MoovPhp\Moov::builder()
    ->setSecurity(
        new Components\Security(
            username: '',
            password: '',
        )
    )
    ->build();

$response = $sdk->endToEndEncryption->generateKey(

);

if ($response->jsonWebKey !== null) {
    // handle response
}
```

## Ask

```java
package hello.world;

import io.moov.sdk.Moov;
import io.moov.sdk.models.components.Security;
import io.moov.sdk.models.operations.GenerateEndToEndKeyResponse;
import java.lang.Exception;

public class Application {

public static void main(String[] args) throws Exception {

Moov sdk = Moov.builder()
                .security(Security.builder()
                    .username("")
                    .password("")
                    .build())
            .build();

GenerateEndToEndKeyResponse res = sdk.endToEndEncryption().generateKey()
                .call();

if (res.jsonWebKey().isPresent()) {
            System.out.println(res.jsonWebKey().get());
        }
    }
}
```

## Ask

```python
from moovio_sdk import Moov
from moovio_sdk.models import components

with Moov(
    security=components.Security(
        username="",
        password="",
    ),
) as moov:

res = moov.end_to_end_encryption.generate_key()

# Handle response
    print(res)
```

## Ask

```ruby
require 'moov_ruby'

Models = ::Moov::Models
s = ::Moov::Client.new(
  security: Models::Components::Security.new(
    username: '',
    password: ''
  )
)
res = s.end_to_end_encryption.generate_key

unless res.json_web_key.nil?
  # handle response
end
```

## Ask

```csharp
using Moov.Sdk;
using Moov.Sdk.Models.Components;

var sdk = new MoovClient(security: new Security() {
    Username = "",
    Password = "",
});

var res = await sdk.EndToEndEncryption.GenerateKeyAsync();

// handle response
```

The request completed successfully.

## Ask

### Example

```json
{
  "alg": "ECDH-ES+A256KW",
  "crv": "P-521",
  "kid": "bOaoOIgm-7dI_gBIvsr0jQrPyYp6H_od0Ok-hSYZQ-g=",
  "kty": "EC",
  "use": "enc",
  "x": "ABcm3wzKpPzYYwjDC0HSrxxVM3ULbuMDUuzkR5wNciaMHkZvQ02gLFdqTL65evV7EWaQyC7zRc28eW20p5MVDdQr",
  "y": "AVa-eQsoiltOcQYy1QEcrQ9NbWktl_D4ewfg8diOZ2_svLEgEu4T1PqNcLbBGozP_VqPkXOMwNCUNI7pxajVGiIP"
}
```

### Response headers

A unique identifier used to trace requests.

Request was refused due to rate limiting.

### Response headers

A unique identifier used to trace requests.

Set this header to v2026.04.00 to use the API described in this specification. When omitted, the server defaults to v2024.01.00, which may not match the behavior documented here.

### Possible values:

`v2026.04.00`

Describes an [RFC7517](https://datatracker.ietf.org/doc/html/rfc7517) web key.

The cryptographic algorithm family used with the key (e.g., 'RSA', 'EC', 'oct').

The algorithm intended for use with the key, e.g., 'RS256' or 'ES256'.

The curve for Elliptic Curve keys, e.g., 'P-256', 'P-384', or 'P-521'.

This field is required when `kty` is 'EC'.

The exponent value for RSA keys.

This field is required when `kty` is 'RSA'.

The permitted operations for the key, e.g., 'sign', 'verify', 'encrypt', 'decrypt'.

A unique identifier for the key.

The modulus value for RSA keys.

This field is required when `kty` is 'RSA'.

The intended use of the key. 'sig' for signature, 'enc' for encryption.

### Possible values:

`sig`,

`enc`

The x coordinate for Elliptic Curve keys.

This field is required when `kty` is 'EC'.

The y coordinate for Elliptic Curve keys.

This field is required when `kty` is 'EC'.
