The signing keys behind your certificates are now tracked as resources of their own. GET /v1/wallets/{walletId}/keys, and the new My Keys page under Trust, show every key, its status, and what is scheduled to happen to it. Request ?include=certificate,certificateSigningRequest to see what each key is used for. Each certificate also carries the keyId of the key it signs with.
A key is reclaimed automatically once every certificate it backs has been revoked or has expired. An imported certificate never gets there, since only the issuing CA can revoke it, so DELETE /v1/wallets/{walletId}/keys/{keyId} releases its key early. It can cost you the ability to revoke, so read deleting a key first. Changed your mind? POST /v1/wallets/{walletId}/keys/{keyId}/cancel-deletion undoes it for the whole grace period, as long as something still needs the key.
Retiring a key takes effect immediately: it stops signing at once rather than when its material is finally erased, and any outstanding credential offers it would have signed are expired along with it.
This is non-breaking, and there is nothing to set up.