Skip to main content
This article lists the maintenance operations available for an API Co-signer. The steps differ by platform, so follow the Maintenance page for your Co-signer type.
Due to the enclave architecture of the Google Cloud Confidential Space Co-signer, maintenance operations can only be performed through Google Cloud’s portal or using gcloud.
Co-signer maintenance include:
  • View the logs
  • Observe the status
  • List the paired API users
  • Retrieve the public key (used for the Callback Handler JWT authentication)
  • Stop the Co-signer
  • Restart the Co-signer
  • Retrieve the running version
  • Update the Co-signer
  • Migrate to a new machine
  • Configure a proxy server
  • Configure the communication protocol
Use the Co-signer management tab to observe the Co-signer’s online or offline status and the list of paired API users. Logs, restarts, upgrades, and the other operations above are on each platform’s Maintenance page.

Check Co-signer status via API

To check whether a Co-signer is online or offline programmatically, call Get API key for an API key paired with the Co-signer. Infer the Co-signer’s status from the lastSeen timestamp in the response — a recent value indicates the Co-signer is online. To find the cosignerId and paired apiKeyId, use Get all cosigners and Get all API keys.