List the bank's encryption targets for an onboarding case
GET/v1/onboarding-cases/:case_id/encryption-targets
Lists the encryption targets registered for the case, oldest first (by created_at,
then id). An encryption target is the key-encryption key (KEK): a symmetric AWS KMS
key in the bank's own AWS account under which the platform wraps the per-message data
keys that encrypt stored transfer source messages. There is at most one target per
purpose; today the only purpose is ENCRYPT_TRANSFER_SOURCE_MESSAGE.
Targets created by a key-generation job appear here too, once the job reaches its
REGISTERING step.
Required scope: connector:onboarding:read. The list is not paginated. A case that does
not exist or belongs to another bank returns an empty list, not 404.
Request
Responses
- 200
- 401
- 403
- 503
Encryption targets with their verification status.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.