Optio Incentives OpenPGP keys
Updated 2026-10-08. A signed plain-text copy of this list is at keys.txt.
These are the OpenPGP keys Optio Incentives uses. Before you trust a key, confirm its fingerprint with Optio through a second channel: a phone call to a person you know at Optio, or a fingerprint you received from us earlier.
Optio Incentives Security
General key for sending secrets to Optio: integration keys, SFTP logins, vulnerability reports. Use this key unless Optio has told you to use a specific one.
- User ID
- Optio Incentives Security <security@optioincentives.com>
- Fingerprint
- 491B F2D1 A899 FE77 AAD4 F328 5385 7474 5495 C885
- Subkey [E]
- A1D8 EA16 0DBC 1D48 CA6E F8F6 3CC9 4D4E B027 DB40
- Algorithm
- RSA 4096 (primary key [SC], encryption subkey [E])
- Created
- 2026-10-08
- Expires
- 2028-10-08
- Public key
- optio-security.asc, also in WKD
Optio Financial Services Limited - HSBC API
Integration key for HSBC Global Payments Solutions. Used only for that integration.
- User ID
- Optio Financial Services Limited - HSBC API <security-ofs@optioincentives.com>
- Fingerprint
- E7C6 9D34 674F FA73 EFC7 44D4 BA1C 8CEA 34C6 5D80
- Subkey [E]
- AD42 2E99 C41A 255D 657E E817 9D5F CB0B A252 D765
- Algorithm
- RSA 4096 (primary key [SC], encryption subkey [E])
- Created
- 2026-10-08
- Expires
- 2028-09-30
- Public key
- optio-ofs-hsbc-api.asc (not in WKD)
- Note
- An earlier user ID on this key, <security@optioincentives.com>, was revoked on 2026-10-08. The fingerprint did not change.
How to verify
Fetch the Security key from Optio's domain over WKD:
gpg --auto-key-locate clear,wkd --locate-keys security@optioincentives.com
Check that the signed list has not been changed:
curl -sO https://openpgpkey.optioincentives.com/keys/keys.txt gpg --verify keys.txt
Then compare the fingerprints with ones you got out of band. A matching signature proves the list came from the holder of the Security key; it does not replace that second check.
Report a security issue: security@optioincentives.com. See also security.txt.