Guides 5 min readUpdated 25 September 2026

eBay says your production keyset is disabled

Your keyset is currently disabled

eBay grants a production keyset and then shows it as disabled, pointing at the marketplace deletion or account closure notification process. Nothing works until that is dealt with.

What eBay is asking for

Every production application must give eBay an address it can notify when an eBay user asks for their personal data to be deleted, and must prove that address belongs to it.

Two things are registered: the endpoint itself, and a verification token you choose. eBay then calls the endpoint with a challenge code and expects a hash of the challenge code, the token and the endpoint address back.

Why verification fails

  • The token registered with eBay differs from the one the application holds, often by a space pasted with it
  • The endpoint address registered differs from the one the application uses to build the hash — a trailing slash or a www is enough
  • The endpoint is not reachable, or answers something other than the expected JSON

Why a test notification can fail with 412

The challenge and the test notification are different things. The challenge is a plain request; the notification is signed, and verifying it means fetching the key eBay signed it with.

eBay hands that key only to an application in the same environment. A production notification arriving at an application still configured for the sandbox cannot be verified at all, and code that treats "could not check" as "invalid" answers 412 and leaves the keyset disabled.

The two cases are worth telling apart: a signature that is present and wrong is a forgery and should be refused; one that cannot be checked should be acknowledged and acted on by nothing.

In order

  • Deploy the endpoint first — eBay checks it during registration
  • Register the endpoint address and the verification token, exactly as the application holds them
  • Save, which triggers the challenge
  • Send the test notification and, if it fails, look at whether the signature could be checked rather than assuming it was wrong

Questions

Can I be exempted?
eBay offers an exemption process for applications that store no eBay user data. If you store any, the endpoint is the route.
Does the endpoint have to be HTTPS?
Yes, and it must be reachable from outside. A local address will not do.
What should the endpoint do with a real notification?
Delete that user’s data. Acknowledging without deleting is only defensible when the notification could not be verified.

Read next