Optio Incentives OpenPGP keys

Updated 2026-10-08. A signed plain-text copy of this list is at keys.txt.

These are the OpenPGP keys Optio Incentives uses. Before you trust a key, confirm its fingerprint with Optio through a second channel: a phone call to a person you know at Optio, or a fingerprint you received from us earlier.

Optio Incentives Security

General key for sending secrets to Optio: integration keys, SFTP logins, vulnerability reports. Use this key unless Optio has told you to use a specific one.

User ID
Optio Incentives Security <security@optioincentives.com>
Fingerprint
491B F2D1 A899 FE77 AAD4 F328 5385 7474 5495 C885
Subkey [E]
A1D8 EA16 0DBC 1D48 CA6E F8F6 3CC9 4D4E B027 DB40
Algorithm
RSA 4096 (primary key [SC], encryption subkey [E])
Created
2026-10-08
Expires
2028-10-08
Public key
optio-security.asc, also in WKD

Optio Financial Services Limited - HSBC API

Integration key for HSBC Global Payments Solutions. Used only for that integration.

User ID
Optio Financial Services Limited - HSBC API <security-ofs@optioincentives.com>
Fingerprint
E7C6 9D34 674F FA73 EFC7 44D4 BA1C 8CEA 34C6 5D80
Subkey [E]
AD42 2E99 C41A 255D 657E E817 9D5F CB0B A252 D765
Algorithm
RSA 4096 (primary key [SC], encryption subkey [E])
Created
2026-10-08
Expires
2028-09-30
Public key
optio-ofs-hsbc-api.asc (not in WKD)
Note
An earlier user ID on this key, <security@optioincentives.com>, was revoked on 2026-10-08. The fingerprint did not change.

How to verify

Fetch the Security key from Optio's domain over WKD:

gpg --auto-key-locate clear,wkd --locate-keys security@optioincentives.com

Check that the signed list has not been changed:

curl -sO https://openpgpkey.optioincentives.com/keys/keys.txt
gpg --verify keys.txt

Then compare the fingerprints with ones you got out of band. A matching signature proves the list came from the holder of the Security key; it does not replace that second check.

Report a security issue: security@optioincentives.com. See also security.txt.