Guides 5 min readUpdated 25 September 2026
eBay says your production keyset is disabled
Your keyset is currently disabled
eBay grants a production keyset and then shows it as disabled, pointing at the marketplace deletion or account closure notification process. Nothing works until that is dealt with.
What eBay is asking for
Every production application must give eBay an address it can notify when an eBay user asks for their personal data to be deleted, and must prove that address belongs to it.
Two things are registered: the endpoint itself, and a verification token you choose. eBay then calls the endpoint with a challenge code and expects a hash of the challenge code, the token and the endpoint address back.
Why verification fails
- The token registered with eBay differs from the one the application holds, often by a space pasted with it
- The endpoint address registered differs from the one the application uses to build the hash — a trailing slash or a www is enough
- The endpoint is not reachable, or answers something other than the expected JSON
Why a test notification can fail with 412
The challenge and the test notification are different things. The challenge is a plain request; the notification is signed, and verifying it means fetching the key eBay signed it with.
eBay hands that key only to an application in the same environment. A production notification arriving at an application still configured for the sandbox cannot be verified at all, and code that treats "could not check" as "invalid" answers 412 and leaves the keyset disabled.
The two cases are worth telling apart: a signature that is present and wrong is a forgery and should be refused; one that cannot be checked should be acknowledged and acted on by nothing.
In order
- Deploy the endpoint first — eBay checks it during registration
- Register the endpoint address and the verification token, exactly as the application holds them
- Save, which triggers the challenge
- Send the test notification and, if it fails, look at whether the signature could be checked rather than assuming it was wrong
Questions
- Can I be exempted?
- eBay offers an exemption process for applications that store no eBay user data. If you store any, the endpoint is the route.
- Does the endpoint have to be HTTPS?
- Yes, and it must be reachable from outside. A local address will not do.
- What should the endpoint do with a real notification?
- Delete that user’s data. Acknowledging without deleting is only defensible when the notification could not be verified.
Read next
- eBay cannot find your business policies
Why eBay reports no business policies when your account plainly has them, what opting in changes, and the inventory location that fails publishing separately.
- eBay business policies, and why publishing fails without them
Payment, postage and returns policies explained, how to opt in, why a listing needs a location to send from, and what each one should say.
- How to import an AliExpress product to eBay
What has to move from an AliExpress page to an eBay listing — photos, description, variations, item specifics — and what goes wrong doing it by hand.