01How it works
The identity linking key is what your own server signs customer ids with, so a
cust on a public pixel or tracking link joins a person's journeys only when it
carries cust_sig:
cust_sig = hex(HMAC-SHA256(linking_key, "<cust_type>:<cust>"))
cust_type defaults to custom; email_md5/email_sha256 digests are signed in lower case.
02Commands
2 under p202 user identity-key.
03For agents
Running this from an agent
- Read the same facts as JSON:
p202 commands user identity-key --json. - With
AI_AGENT,CLAUDECODEor another agent variable set, output is compact JSON and errors arrive on stderr as a JSON envelope with ahint. - Exit codes: 0 ok, 1 bad input, 2 auth, 3 network, 4 server error, 5 partial failure.
{
"path": "p202 user identity-key",
"use": "identity-key",
"short": "Show or rotate the key your server signs customer ids with",
"long": "The identity linking key is what your own server signs customer ids with, so a\n`cust` on a public pixel or tracking link joins a person's journeys only when it\ncarries `cust_sig`:\n\n cust_sig = hex(HMAC-SHA256(linking_key, \"<cust_type>:<cust>\"))\n\ncust_type defaults to custom; email_md5/email_sha256 digests are signed in lower case.",
"runnable": false
}