This section defines how partners generate, register, operate, and maintain cryptographic materials required for signing and encryption.
Generate Partner Private Key and CSR
This subsection describes the CSR workflow used to establish certificate-based trust during onboarding.
Partners generate:
An RSA private key (partner-owned secret).
A CSR containing the partner public key and identifying attributes.
CSR constraints
The CSR Common Name (CN) SHALL match the partner domain FQDN used for service integration.
Register Certificate Information in Partner Portal
This subsection defines how onboarding-related encryption settings and certificate information are registered.
Partners configure the service encryption mode (e.g., End-to-End Encryption) and register CSR information through the Partner Portal. Multiple certificate registrations MAY be supported for staged migration, and encryption settings MAY be constrained after issuance depending on portal policy.
Certificate Identifiers and Token References
This subsection defines the identifiers used to reference onboarding artifacts in runtime tokens.
certificateId: Identifier issued for the certificate registered/issued via CSR onboarding; used in tokens and selected API paths.
partnerId: Partner identifier assigned during Partner Portal registration (also used as/alongside partnerCode terminology).
Key Rotation and Incident Response (Recommended)
This subsection provides an operational model for rotating key materials and responding to key compromise.
Recommended rotation
Generate a new private key and CSR.
Register a new certificate while keeping the existing certificate active.
Begin issuing tokens with the new certificateId.
Retire the old key after migration.
Incident response
If compromise is suspected, stop issuing tokens with the affected key immediately, generate new credentials, and rotate the operational secrets.
Manage Your Cookies
We use cookies to improve your experience on our website and to show you relevant
advertising. Manage you settings for our cookies below.
Essential Cookies
These cookies are essential as they enable you to move around the website. This
category cannot be disabled.
Company
Domain
Samsung Electronics
developer.samsung.com, .samsung.com
Analytical/Performance Cookies
These cookies collect information about how you use our website. for example which
pages you visit most often. All information these cookies collect is used to improve
how the website works.
Company
Domain
Samsung Electronics
.samsung.com
Functionality Cookies
These cookies allow our website to remember choices you make (such as your user name, language or the region your are in) and
tailor the website to provide enhanced features and content for you.
Company
Domain
Samsung Electronics
developer.samsung.com, google.account.samsung.com
Preferences Submitted
You have successfully updated your cookie preferences.